Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vf79-gc8c-5h95

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 50.

An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 50.

EPSS

Процентиль: 85%
0.02551
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 50.

CVSS3: 9.8
redhat
около 9 лет назад

An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 50.

CVSS3: 9.8
nvd
больше 7 лет назад

An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 50.

CVSS3: 9.8
debian
больше 7 лет назад

An issue where WebExtensions can use the mozAddonManager API to elevat ...

suse-cvrf
около 9 лет назад

Security update for MozillaFirefox, mozilla-nss

EPSS

Процентиль: 85%
0.02551
Низкий

9.8 Critical

CVSS3