Release Date: | 2025-04-29 | |
Impact: | Moderate | What is this? |
A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. This bypasses public suffix protections and could allow a malicious website to set cookies for domains it does not own, potentially leading to integrity issues such as session fixation.
See more information about CVE-2025-4035 from MITRE CVE dictionary and NIST NVD
NOTE: The following CVSS metrics and score provided are preliminary and subject to review.
Base Score: | 4.3 |
Vector String: | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Version: | 3.1 |
Attack Vector: | Network |
Attack Complexity: | Low |
Privileges Required: | None |
User Interaction: | Required |
Scope: | Unchanged |
Confidentiality Impact: | None |
Integrity Impact: | Low |
Availability Impact: | None |
Platform | Errata | Release Date |
Oracle Linux version 10 (libsoup3) | ELSA-2025-8128 | 2025-06-26 |
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections: