Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5mrh-6gmv-vc85

Опубликовано: 02 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Under specific circumstances a WebExtension may have received a jar:file:/// URI instead of a moz-extension:/// URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

Under specific circumstances a WebExtension may have received a jar:file:/// URI instead of a moz-extension:/// URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

EPSS

Процентиль: 32%
0.00124
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 2 лет назад

Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

CVSS3: 4.3
nvd
больше 2 лет назад

Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

CVSS3: 4.3
debian
больше 2 лет назад

Under specific circumstances a WebExtension may have received a <code> ...

CVSS3: 4.3
fstec
почти 5 лет назад

Уязвимость компонента WebExtension веб-браузера Firefox, связанная с раскрытием информации в ошибочной области данных, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 32%
0.00124
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-668