Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-5115

Опубликовано: 11 июн. 2018
Источник: debian
EPSS Низкий

Описание

If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed over the currently loaded foreground page. Although the prompt contains the real domain making the request, this can result in user confusion about the originating site of the authentication request and may cause users to mistakenly send private credential information to a third party site. This vulnerability affects Firefox < 58.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed58.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-02/#CVE-2018-5115

EPSS

Процентиль: 82%
0.0171
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed over the currently loaded foreground page. Although the prompt contains the real domain making the request, this can result in user confusion about the originating site of the authentication request and may cause users to mistakenly send private credential information to a third party site. This vulnerability affects Firefox < 58.

CVSS3: 7.5
nvd
больше 7 лет назад

If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed over the currently loaded foreground page. Although the prompt contains the real domain making the request, this can result in user confusion about the originating site of the authentication request and may cause users to mistakenly send private credential information to a third party site. This vulnerability affects Firefox < 58.

CVSS3: 7.5
github
больше 3 лет назад

If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed over the currently loaded foreground page. Although the prompt contains the real domain making the request, this can result in user confusion about the originating site of the authentication request and may cause users to mistakenly send private credential information to a third party site. This vulnerability affects Firefox < 58.

CVSS3: 5.3
fstec
больше 8 лет назад

Уязвимость браузера Mozilla Firefox, связанная с ошибкой аунтефикации при HTTP запросе, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 82%
0.0171
Низкий