Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5mp2-hvxf-rx92

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.

EPSS

Процентиль: 29%
0.00108
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 11 лет назад

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.

redhat
почти 11 лет назад

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.

nvd
почти 11 лет назад

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.

debian
почти 11 лет назад

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 ...

fstec
почти 11 лет назад

Уязвимость браузера Firefox, позволяющая удалённому злоумышленнику обойти проверку сертификата

EPSS

Процентиль: 29%
0.00108
Низкий

Дефекты

CWE-20