-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| codeigniter4/framework | composer | < 4.2.7 | 4.2.7 |
The vulnerability stems from both functions using hardcoded default values (false) for $secure and $httponly parameters instead of respecting the Config\Cookie settings when cookies were created via array parameters. This is confirmed by the documented workaround requiring explicit parameter specification and the patch notes indicating configuration values weren't being properly initialized. Both functions are directly mentioned in the vulnerability description as affected endpoints.
Ongoing coverage of React2Shell