CVE-2022-40958
UNKNOWN
Published 2022-12-22T00:00:00.000Z
Actions:
CVSS Score
V3.1
6.5
/10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Base Score Metrics
Exploitability: N/A
Impact: N/A
EPSS Score
v2023.03.01
0.001
probability
of exploitation in the wild
There is a 0.1% chance that this vulnerability will be exploited in the wild within the next 30 days.
Updated: 2025-01-25
Exploit Probability
Percentile: 0.441
Higher than 44.1% of all CVEs
Attack Vector Metrics
Impact Metrics
Description
By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite cookies from a secure context, leading to session fixation and other attacks. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
Available Exploits
No exploits available for this CVE.
Related News
No news articles found for this CVE.
Affected Products
Affected Versions:
Affected Versions:
Affected Versions:
References
Published: 2022-12-22T00:00:00.000Z
Last Modified: 2025-04-15T14:55:52.463Z
Copied to clipboard!