CVE-2022-39284: Codeigniter4's Secure or HttpOnly flag set in Config\Cookie is not reflected in Cookies issued
2.6
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.35501%
CWE
Published
10/6/2022
Updated
7/12/2023
KEV Status
No
Technology
PHP
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| codeigniter4/framework | composer | < 4.2.7 | 4.2.7 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability stems from both functions using hardcoded default values (false) for $secure and $httponly parameters instead of respecting the Config\Cookie settings when cookies were created via array parameters. This is confirmed by the documented workaround requiring explicit parameter specification and the patch notes indicating configuration values weren't being properly initialized. Both functions are directly mentioned in the vulnerability description as affected endpoints.