HomeDefectsLIN1024-389
Acknowledged

LIN1024-389 : Security Advisory - php - CVE-2024-2756

Created: Apr 29, 2024    Updated: Jan 7, 2026
Resolved Date: Jun 6, 2024
Found In Version: 10.24.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Userspace

Description

Due to an incomplete fix to  CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applications. 

https://nvd.nist.gov/vuln/detail/CVE-2024-2756