CVE-2008-7297

Opera Browser - Cookie Manipulation via HTTP Set-Cookie Header

Title source: llm
STIX 2.1

Description

Opera cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.

Scores

EPSS 0.0043
EPSS Percentile 63.0%

Details

CWE
CWE-264
Status published
Products (1)
opera/opera_browser
Published Aug 09, 2011
Tracked Since Feb 18, 2026