CVE-2022-40958: Medium severity thunderbird vulnerability
By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite cookies from a secure context, leading to session fixation and other attacks.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-40958.
What is the severity level of CVE-2022-40958?
The severity level of CVE-2022-40958 is medium.
Which software products are affected by CVE-2022-40958?
CVE-2022-40958 affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
How can an attacker exploit CVE-2022-40958?
An attacker can exploit CVE-2022-40958 by injecting a cookie with certain special characters on a shared subdomain to set and overwrite cookies from a secure context.
Are there any known remediation steps for CVE-2022-40958?
Yes, updating to Firefox ESR version 102.3 or higher, Thunderbird version 102.3 or higher, or Firefox version 105 or higher will remediate CVE-2022-40958.