Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-85vg-hqhq-qvx3

Опубликовано: 01 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

EPSS

Процентиль: 50%
0.00273
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 2 года назад

Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 7.5
redhat
почти 2 года назад

Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 5.3
nvd
почти 2 года назад

Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 5.3
debian
почти 2 года назад

Offscreen Canvas did not properly track cross-origin tainting, which c ...

CVSS3: 9.8
fstec
почти 2 года назад

Уязвимость функции OffscreenCanvas браузеров Firefox, Firefox ESR , позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 50%
0.00273
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-346