cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.
Product | Vendor | Version |
---|---|---|
n/a | n/a | Build date before 230821(Version before V4.1.60 are not affected) |