A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.
The SameSite attribute for sensitive cookies is not set, or an insecure value is used.
Link | Tags |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1844827 | issue tracking |
https://www.mozilla.org/security/advisories/mfsa2024-29/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2024-32/ | vendor advisory |