Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-6868

Опубликовано: 19 дек. 2023
Источник: debian
EPSS Низкий

Описание

In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. *This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxnot-affectedpackage

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2023-56/#CVE-2023-6868

EPSS

Процентиль: 41%
0.00222
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 2 года назад

In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. *This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121.

CVSS3: 4.3
nvd
почти 2 года назад

In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. *This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121.

CVSS3: 4.3
github
почти 2 года назад

In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. *This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121.

CVSS3: 5.3
fstec
почти 2 года назад

Уязвимость push-уведомлений браузера Mozilla Firefox операционных систем Android, позволяющая нарушителю получить несанкционированный доступ к ограниченным функциям

EPSS

Процентиль: 41%
0.00222
Низкий