Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3h65-3mjq-qqj8

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact with them, bypassing same-origin user expectations with this permission. This vulnerability affects Firefox < 58.

WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact with them, bypassing same-origin user expectations with this permission. This vulnerability affects Firefox < 58.

EPSS

Процентиль: 65%
0.00487
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact with them, bypassing same-origin user expectations with this permission. This vulnerability affects Firefox < 58.

CVSS3: 9.8
nvd
больше 7 лет назад

WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact with them, bypassing same-origin user expectations with this permission. This vulnerability affects Firefox < 58.

CVSS3: 9.8
debian
больше 7 лет назад

WebExtensions with the "ActiveTab" permission are able to access frame ...

CVSS3: 9.8
fstec
больше 8 лет назад

Уязвимость расширения WebExtensions браузера Mozilla Firefox, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 65%
0.00487
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-346