Description

A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. This bypasses public suffix protections and could allow a malicious website to set cookies for domains it does not own, potentially leading to integrity issues such as session fixation.

INFO

Published Date :

2025-04-29T12:56:22.726Z

Last Modified :

2025-11-18T08:35:54.319Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2025-4035 vulnerability.

Vendors Products
Redhat
  • Enterprise Linux

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact