Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p4q7-g7ff-823j

Опубликовано: 07 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4

Описание

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.

EPSS

Процентиль: 5%
0.00023
Низкий

4 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 4
ubuntu
5 месяцев назад

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 5.4
redhat
5 месяцев назад

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 4
nvd
5 месяцев назад

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 4
debian
5 месяцев назад

When using Alt-Svc, ALPN did not properly validate certificates when t ...

CVSS3: 5.4
fstec
5 месяцев назад

Уязвимость компонента Application-Layer Protocol Negotiation (ALPN) браузеров Mozilla Firefox, Firefox ESR и почтовых клиентов Thunderbird, Thunderbird ESR, позволяющая нарушителю перенаправить пользователя на произвольный URL-адрес

EPSS

Процентиль: 5%
0.00023
Низкий

4 Medium

CVSS3

Дефекты

CWE-295