Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-6868

Опубликовано: 19 дек. 2023
Источник: debian
EPSS Низкий

Описание

In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. *This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxnot-affectedpackage

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2023-56/#CVE-2023-6868

EPSS

Процентиль: 33%
0.00128
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 2 лет назад

In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. *This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121.

CVSS3: 4.3
nvd
около 2 лет назад

In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. *This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121.

CVSS3: 4.3
github
около 2 лет назад

In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. *This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121.

CVSS3: 5.3
fstec
около 2 лет назад

Уязвимость push-уведомлений браузера Mozilla Firefox операционных систем Android, позволяющая нарушителю получить несанкционированный доступ к ограниченным функциям

EPSS

Процентиль: 33%
0.00128
Низкий