Medium severity6.5NVD Advisory· Published Jun 2, 2023· Updated Jun 17, 2026
CVE-2023-29547
CVE-2023-29547
Description
When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, when it should have silently failed. This could have led to a desynchronization in expected results when reading from the secure cookie. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10<112+ 3 more
- (no CPE)range: <112
- (no CPE)range: unspecified
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <112.0
- cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*range: <102.10
<112+ 1 more
- (no CPE)range: <112
- (no CPE)range: unspecified
- Range: unspecified
- osv-coords2 versionspkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweed
< 112.0.1-1.1+ 1 more
- (no CPE)range: < 112.0.1-1.1
- (no CPE)range: < 128.5.1-1.1
Patches
Vulnerability mechanics
References
2- www.mozilla.org/security/advisories/mfsa2023-13/nvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdIssue Tracking
News mentions
0No linked articles in our index yet.