VYPR

Firebase Javascript SDK

by Google

CVEs (1)

  • CVE-2024-11023MedNov 18, 2024
    risk 0.33cvss 6.1epss 0.00

    Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncURL" field used for session synchronization. If this cookie field is preset via an attacker by any other method, the attacker can manipulate the…