Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hmhq-whfw-x78q

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port - would be granted that permission. This bug only affects Firefox for Android. Other operating systems are unaffected.. This vulnerability affects Firefox < 90.

If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port - would be granted that permission. This bug only affects Firefox for Android. Other operating systems are unaffected.. This vulnerability affects Firefox < 90.

EPSS

Процентиль: 61%
0.00412
Низкий

Дефекты

CWE-281

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port - would be granted that permission. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 90.

CVSS3: 9.8
nvd
больше 4 лет назад

If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port - would be granted that permission. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 90.

CVSS3: 9.8
debian
больше 4 лет назад

If a user had granted a permission to a webpage and saved that grant, ...

CVSS3: 5.4
fstec
больше 4 лет назад

Уязвимость браузера Mozilla Firefox для Android, связанная с недостатками разграничения доступа, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 61%
0.00412
Низкий

Дефекты

CWE-281