Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-823q-pcrj-c4xv

Опубликовано: 26 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

An attacker was able to bypass the connect-src directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140.

An attacker was able to bypass the connect-src directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140.

EPSS

Процентиль: 22%
0.003
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-693

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 1 года назад

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

CVSS3: 6.1
redhat
около 1 года назад

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

CVSS3: 9.1
nvd
около 1 года назад

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

CVSS3: 9.1
debian
около 1 года назад

An attacker was able to bypass the `connect-src` directive of a Conten ...

CVSS3: 9.1
fstec
около 1 года назад

Уязвимость механизма Content Security Policy (CSP) браузера Mozilla Firefox, позволяющая нарушителю обойти ограничения безопасности и получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 22%
0.003
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-693