Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vp8c-39q7-pxqc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

EPSS

Процентиль: 80%
0.02131
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-116

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 7 лет назад

A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.1
redhat
около 7 лет назад

A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 5.3
nvd
около 7 лет назад

A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 5.3
debian
около 7 лет назад

A vulnerability exists where the caret ("^") character is improperly e ...

CVSS3: 5.3
fstec
около 7 лет назад

Уязвимость почтового клиента Thunderbird и браузеров Firefox и Firefox ESR, связанная с ошибками экранирования символа каретки("^"), позволяющая нарушителю нарушить целостность данных

EPSS

Процентиль: 80%
0.02131
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-116