Loading HuntDB...

GHSA-gvhf-4hjq-39hg

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

Related CVEs

Key Information

GHSA ID
GHSA-gvhf-4hjq-39hg
Published
December 22, 2022 9:30 PM
Last Modified
April 15, 2025 3:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 9, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.