Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3xch-57qj-5x2p

Опубликовано: 19 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. This bug only affects Firefox on Android. This vulnerability affects Firefox < 121.

In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. This bug only affects Firefox on Android. This vulnerability affects Firefox < 121.

EPSS

Процентиль: 41%
0.00222
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 2 года назад

In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. *This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121.

CVSS3: 4.3
nvd
почти 2 года назад

In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. *This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121.

CVSS3: 4.3
debian
почти 2 года назад

In some instances, the user-agent would allow push requests which lack ...

CVSS3: 5.3
fstec
почти 2 года назад

Уязвимость push-уведомлений браузера Mozilla Firefox операционных систем Android, позволяющая нарушителю получить несанкционированный доступ к ограниченным функциям

EPSS

Процентиль: 41%
0.00222
Низкий

4.3 Medium

CVSS3