The classifier judged this item not relevant to AI security, so it is left out of lists, feeds, the API and dataset releases. If that is wrong, report a correction on this page.
MediumVulnerability
GHSA-g4qm-m288-5cp9: Coraza has Cookie Parser Confusion
- Identifier
- GHSA-g4qm-m288-5cp9
- Published
- Record updated
Summary
Coraza's cookie parser, internal/cookies.ParseCookies, trims only space and tab from cookie names and values, so a control character placed next to the `=` separator stays in the name or value. Several backend parsers strip it, so the WAF and the application can index different cookies, letting a SecRule scoped to a cookie name or value miss cookies that the application processes. The fix is in Coraza 3.8.0, per the version noted in the divergence table as affected below 3.8.0.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.