Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2wfq-mq88-h9xc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This vulnerability affects Firefox < 83.

Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This vulnerability affects Firefox < 83.

EPSS

Процентиль: 44%
0.00219
Низкий

Дефекты

CWE-1021

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 5 лет назад

Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This vulnerability affects Firefox < 83.

CVSS3: 6.1
nvd
около 5 лет назад

Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This vulnerability affects Firefox < 83.

CVSS3: 6.1
debian
около 5 лет назад

Cross-origin iframes that contained a login form could have been recog ...

EPSS

Процентиль: 44%
0.00219
Низкий

Дефекты

CWE-1021