Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2m96-7r2c-fq6j

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possible for the Web Extension to read local files. This vulnerability affects Firefox < 74.

When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possible for the Web Extension to read local files. This vulnerability affects Firefox < 74.

EPSS

Процентиль: 63%
0.00458
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possible for the Web Extension to read local files. This vulnerability affects Firefox < 74.

CVSS3: 7.5
redhat
почти 6 лет назад

When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possible for the Web Extension to read local files. This vulnerability affects Firefox < 74.

CVSS3: 7.5
nvd
почти 6 лет назад

When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possible for the Web Extension to read local files. This vulnerability affects Firefox < 74.

CVSS3: 7.5
debian
почти 6 лет назад

When a Web Extension had the all-urls permission and made a fetch requ ...

EPSS

Процентиль: 63%
0.00458
Низкий

Дефекты

CWE-200