Explore

Rule Explorer

Search the public rule index by CVE, GHSA, CWE, language, framework, author, or rule slug. Filter by language, framework, severity, confidence, license, and validation status.

Public rules
2917
Downloads
3.3M
Verified
2917
Authors
2
Search the rule indexUse CVE, GHSA, CWE, language, framework, package, or rule slug.
1 rules matched. Showing 1 loaded rules.
Publish rule
CVE-2024-11023: Firebase Sdk Auth Token Sync Url Leakcve-2024-11023-firebase-sdk-auth-token-sync-url-leak

The application retrieves the 'authTokenSyncURL' experimental configuration but fails to verify that it represents a local domain path. An attacker who can pre-set the corresponding cookie (e.g., FIREBASE_DEFAULTS) could direct auth tokens to an external server. Ensure the URL is validated to start with '/' before usage.

by Provallyupdated 2026-06-12Apache-2.0
1K0 direct1K via packs
downloads
73quality
All matching rules loaded.