Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3mrp-wph9-cw58

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.3

Описание

Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed. This vulnerability affects Firefox < 68.

Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed. This vulnerability affects Firefox < 68.

EPSS

Процентиль: 68%
0.00583
Низкий

8.3 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.3
ubuntu
больше 6 лет назад

Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed. This vulnerability affects Firefox < 68.

CVSS3: 8.3
redhat
больше 6 лет назад

Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed. This vulnerability affects Firefox < 68.

CVSS3: 8.3
nvd
больше 6 лет назад

Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed. This vulnerability affects Firefox < 68.

CVSS3: 8.3
debian
больше 6 лет назад

Until explicitly accessed by script, window.globalThis is not enumerab ...

CVSS3: 8.3
fstec
больше 6 лет назад

Уязвимость компонента window.globalThis браузера Firefox, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 68%
0.00583
Низкий

8.3 High

CVSS3

Дефекты

CWE-20