Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-823q-pcrj-c4xv

Опубликовано: 26 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

An attacker was able to bypass the connect-src directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140.

An attacker was able to bypass the connect-src directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140.

EPSS

Процентиль: 12%
0.0004
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-693

Связанные уязвимости

CVSS3: 9.1
ubuntu
6 месяцев назад

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140 and Thunderbird < 140.

CVSS3: 6.1
redhat
6 месяцев назад

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140 and Thunderbird < 140.

CVSS3: 9.1
nvd
6 месяцев назад

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140 and Thunderbird < 140.

CVSS3: 9.1
debian
6 месяцев назад

An attacker was able to bypass the `connect-src` directive of a Conten ...

CVSS3: 9.1
fstec
6 месяцев назад

Уязвимость механизма Content Security Policy (CSP) браузера Mozilla Firefox, позволяющая нарушителю обойти ограничения безопасности и получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 12%
0.0004
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-693