Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7g8j-7wv5-6f7h

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing the domain of the current page. This vulnerability affects Firefox < 54.

When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing the domain of the current page. This vulnerability affects Firefox < 54.

EPSS

Процентиль: 67%
0.0054
Низкий

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing the domain of the current page. This vulnerability affects Firefox < 54.

CVSS3: 7.5
redhat
больше 8 лет назад

When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing the domain of the current page. This vulnerability affects Firefox < 54.

CVSS3: 7.5
nvd
больше 7 лет назад

When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing the domain of the current page. This vulnerability affects Firefox < 54.

CVSS3: 7.5
debian
больше 7 лет назад

When entered directly, Reader Mode did not strip the username and pass ...

oracle-oval
больше 7 лет назад

ELSA-2018-2113: firefox security update (CRITICAL)

EPSS

Процентиль: 67%
0.0054
Низкий

7.5 High

CVSS3

Дефекты

CWE-20