Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-887x-j4cf-3pqh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 2.8

Описание

Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open. Subsequently, if the user had opened a new Private Browsing Window, revisited the same site, and generated a new password - the generated passwords would have been identical, rather than independent. This vulnerability affects Firefox < 75.

Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open. Subsequently, if the user had opened a new Private Browsing Window, revisited the same site, and generated a new password - the generated passwords would have been identical, rather than independent. This vulnerability affects Firefox < 75.

EPSS

Процентиль: 33%
0.00132
Низкий

2.8 Low

CVSS3

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 2.8
ubuntu
почти 6 лет назад

Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open. Subsequently, if the user had opened a new Private Browsing Window, revisited the same site, and generated a new password - the generated passwords would have been identical, rather than independent. This vulnerability affects Firefox < 75.

CVSS3: 2.8
redhat
почти 6 лет назад

Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open. Subsequently, if the user had opened a new Private Browsing Window, revisited the same site, and generated a new password - the generated passwords would have been identical, rather than independent. This vulnerability affects Firefox < 75.

CVSS3: 2.8
nvd
почти 6 лет назад

Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open. Subsequently, if the user had opened a new Private Browsing Window, revisited the same site, and generated a new password - the generated passwords would have been identical, rather than independent. This vulnerability affects Firefox < 75.

CVSS3: 2.8
debian
почти 6 лет назад

Initially, a user opens a Private Browsing Window and generates a pass ...

EPSS

Процентиль: 33%
0.00132
Низкий

2.8 Low

CVSS3

Дефекты

CWE-384