CVE-2008-7294 - CVE House
Back to Database
Status published Medium CVE-2008-7294

Google Chrome before 4.0.211.0 cannot properly restrict modifications to cookies...

Vulnerability Description

Google Chrome before 4.0.211.0 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-7294

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

chrome
Vulnerable Versions:
0, 0.1.38.1, 0.1.38.2, 0.1.38.4, 0.1.40.1, 0.1.42.2, 0.1.42.3, 0.2.149.27, 0.2.149.29, 0.2.149.30, 0.2.152.1, 0.2.153.1, 0.3.154.0, 0.3.154.3, 0.4.154.18, 0.4.154.22, 0.4.154.31, 0.4.154.33, 1.0.154.36, 1.0.154.39, 1.0.154.42, 1.0.154.43, 1.0.154.46, 1.0.154.48, 1.0.154.52, 1.0.154.53, 1.0.154.59, 1.0.154.64, 1.0.154.65, 2.0.156.1, 2.0.157.0, 2.0.157.2, 2.0.158.0, 2.0.159.0, 2.0.169.0, 2.0.169.1, 2.0.170.0, 2.0.172, 2.0.172.2, 2.0.172.8, 2.0.172.27, 2.0.172.28, 2.0.172.30, 2.0.172.31, 2.0.172.33, 2.0.172.37, 2.0.172.38, 3.0.182.2, 3.0.190.2, 3.0.193.2, 3.0.195.2, 3.0.195.21, 3.0.195.24, 3.0.195.25, 3.0.195.27, 3.0.195.32, 3.0.195.33, 3.0.195.36, 3.0.195.37

Timeline

Official Publish: August 9th, 2011
Last Modified: September 17th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.