Firebase JavaScript SDK allows attackers to manipulate the "_authTokenSyncURL" to point to their own server
- Severity:
- Medium
Description
Firebase JavaScript SDK utilizes a “FIREBASE_DEFAULTS” cookie to store configuration data, including an “_authTokenSyncURL” field used for session synchronization.
Recommendation
Update the firebase package to the latest compatible version. Followings are version details:
- Affected version(s): < 10.9.0
- Patched version(s): 10.9.0
References
Related Issues
- AngularJS allows attackers to bypass common image source restrictions (GHSA-mqm9-c95h-x2p6) - CVE-2024-8373
- AngularJS allows attackers to bypass common image source restrictions - CVE-2024-8372
- Strapi allows Server-Side Request Forgery in Webhook function - CVE-2024-52588
- matrix-js-sdk has insufficient MXC URI validation which allows client-side path traversal - CVE-2024-50336
- Tags:
- npm
- firebase
Anything's wrong? Let us know Last updated on November 18, 2024