CVE-2023-4055: High severity thunderbird vulnerability
Last updated 24 July 2024
Other sources
When the number of cookies per domain was exceeded in document.cookie, the actual cookie jar sent to the host was no longer consistent with expected cookie jar state. This could have caused requests to be sent with some cookies missing.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-30/#CVE-2023-4055
— Red Hat
When the number of cookies per domain was exceeded in document.cookie, the actual cookie jar sent to the host was no longer consistent with expected cookie jar state. This could have caused requests to be sent with some cookies missing. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
When the number of cookies per domain was exceeded in document.cookie, the actual cookie jar sent to the host was no longer consistent with expected cookie jar state. This could have caused requests to be sent with some cookies missing.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-4055?
CVE-2023-4055 is a vulnerability that occurs when the number of cookies per domain exceeds the limit in `document.cookie`, which may result in requests being sent with some cookies missing.
Which software is affected by CVE-2023-4055?
CVE-2023-4055 affects Mozilla Thunderbird versions up to 115.1, Mozilla Firefox versions up to 116, and their corresponding packages in Red Hat and Ubuntu.
What is the severity of CVE-2023-4055?
CVE-2023-4055 has a severity rating of 7.5 (high).
How can I fix CVE-2023-4055?
To fix CVE-2023-4055, update Mozilla Thunderbird to version 115.1 or later, update Mozilla Firefox to version 116 or later, and apply the necessary security patches for the affected packages in Red Hat or Ubuntu.
Where can I find more information about CVE-2023-4055?
You can find more information about CVE-2023-4055 in the Mozilla Security Advisories MFSA2023-30 and MFSA2023-31, as well as the Bugzilla report.