By exploiting other vulnerabilities in the server, the attacker-controlled cookie can be used to access private information.

According to the researchers , Google and Bank of America are affected by this vulnerability.

End-users should update their browsers to ensure that they have full HSTS support, CERT said.

Cookies from HTTPS sessions can leak data

Thus, one server can be used to leverage an attack against the other.

spot_img

source: www.techworm.net