Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5mp2-hvxf-rx92

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.

EPSS

Процентиль: 64%
0.01174
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 11 лет назад

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.

redhat
больше 11 лет назад

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.

nvd
больше 11 лет назад

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.

debian
больше 11 лет назад

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 ...

fstec
больше 11 лет назад

Уязвимость браузера Firefox, позволяющая удалённому злоумышленнику обойти проверку сертификата

EPSS

Процентиль: 64%
0.01174
Низкий

Дефекты

CWE-20