{"id":"CVE-2024-11023","aliases":["GHSA-3wf4-68gx-mph8"],"url":"https://o3.security/vulnerability/CVE-2024-11023","summary":"Session Hijacking in Firebase JavaScript SDK","details":"Firebase JavaScript SDK utilizes a \"FIREBASE_DEFAULTS\" cookie to store configuration data, including an \"_authTokenSyncURL\" field used for session synchronization.  If this cookie field is preset via an attacker by any other method, the attacker can manipulate the \"_authTokenSyncURL\" to point to their own server and it would allow an actor to capture user session data transmitted by the SDK. We recommend upgrading Firebase JS SDK at least to 10.9.0.","published":"2024-11-18T10:19:54.581Z","modified":"2026-07-15T01:49:18.773984919Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"firebase","fixedVersion":"10.9.0"}],"fix":{"url":"https://github.com/firebase/firebase-js-sdk/pull/8056","label":"firebase/firebase-js-sdk#8056"},"references":[{"type":"WEB","url":"https://firebase.google.com/support/release-notes/js#version_1090_-_march_14_2024"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/11xxx/CVE-2024-11023.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-11023"},{"type":"FIX","url":"https://github.com/firebase/firebase-js-sdk/pull/8056"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:18.773984919Z"}}