Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4765-j7w9-p387

Опубликовано: 22 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

EPSS

Процентиль: 39%
0.00171
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-942

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 2 лет назад

A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 9.8
redhat
около 3 лет назад

A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 9.8
nvd
больше 2 лет назад

A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 9.8
debian
больше 2 лет назад

A malicious website could have learned the size of a cross-origin reso ...

CVSS3: 7.5
fstec
около 3 лет назад

Уязвимость реализации механизма CORS (Cross-Origin Resource Sharing) браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю обойти ограничения безопасности

EPSS

Процентиль: 39%
0.00171
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-942