Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fjjp-3m6f-4p7r

Опубликовано: 10 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to bypass the content-security-policy configuration.

A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to bypass the content-security-policy configuration.

EPSS

Процентиль: 39%
0.00171
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 2 лет назад

A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to bypass the content-security-policy configuration.

EPSS

Процентиль: 39%
0.00171
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79