Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-38xr-6jm2-v69w

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.

Ссылки

EPSS

Процентиль: 40%
0.00181
Низкий

Дефекты

CWE-352

Связанные уязвимости

ubuntu
почти 11 лет назад

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.

redhat
почти 11 лет назад

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.

nvd
почти 11 лет назад

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.

debian
почти 11 лет назад

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0 ...

oracle-oval
почти 11 лет назад

ELSA-2015-0047: thunderbird security update (IMPORTANT)

EPSS

Процентиль: 40%
0.00181
Низкий

Дефекты

CWE-352