Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cvqq-hjjc-jrc6

Опубликовано: 22 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, resulting in incorrect error pages being shown. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, resulting in incorrect error pages being shown. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

EPSS

Процентиль: 35%
0.00141
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-703

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 2 лет назад

If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, resulting in incorrect error pages being shown. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

CVSS3: 6.1
redhat
почти 3 года назад

If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, resulting in incorrect error pages being shown. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

CVSS3: 4.3
nvd
больше 2 лет назад

If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, resulting in incorrect error pages being shown. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

CVSS3: 4.3
debian
больше 2 лет назад

If there was a PAC URL set and the server that hosts the PAC was not r ...

CVSS3: 6.1
fstec
почти 3 года назад

Уязвимость почтового клиента Thunderbird, браузеров Firefox и Firefox ESR, связанная с неправильной обработкой ошибок при обработке недоступного PAC-файла, позволяющая нарушителю задать URL-адрес PAC, и если сервер, на котором размещен PAC, недоступен, запросы OCSP блокируются, что приводит к отображению неверных страниц ошибок

EPSS

Процентиль: 35%
0.00141
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-703