Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-8031

Опубликовано: 22 июл. 2025
Источник: debian
EPSS Низкий

Описание

The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed141.0-1package
firefox-esrfixed128.13.0esr-1package
thunderbirdfixed1:128.13.0esr-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-56/#CVE-2025-8031

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-58/#CVE-2025-8031

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-62/#CVE-2025-8031

EPSS

Процентиль: 30%
0.00108
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
14 дней назад

The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.

CVSS3: 6.1
redhat
14 дней назад

The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.

CVSS3: 9.8
nvd
14 дней назад

The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.

CVSS3: 9.8
github
14 дней назад

The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.

rocky
8 дней назад

Important: firefox security update

EPSS

Процентиль: 30%
0.00108
Низкий