Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-34477

Опубликовано: 22 дек. 2022
Источник: debian
EPSS Низкий

Описание

The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site cross-origin resource, the message could have leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 102.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed102.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2022-24/#CVE-2022-34477

EPSS

Процентиль: 57%
0.00353
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site cross-origin resource, the message could have leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 102.

CVSS3: 7.5
nvd
около 3 лет назад

The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site cross-origin resource, the message could have leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 102.

CVSS3: 7.5
github
около 3 лет назад

The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site cross-origin resource, the message could have leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 102.

suse-cvrf
больше 3 лет назад

Security update for MozillaFirefox

suse-cvrf
больше 3 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 57%
0.00353
Низкий