Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4h8f-5jwq-q4wm

Опубликовано: 22 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.

When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.

EPSS

Процентиль: 37%
0.00158
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.

CVSS3: 6.5
nvd
почти 3 года назад

When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.

CVSS3: 6.5
debian
почти 3 года назад

When downloading an update for an addon, the downloaded addon update's ...

suse-cvrf
около 3 лет назад

Security update for MozillaFirefox

suse-cvrf
около 3 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 37%
0.00158
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-345