Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vpgc-chc4-fq2j

Опубликовано: 01 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

EPSS

Процентиль: 37%
0.00149
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-1021

Связанные уязвимости

CVSS3: 6.1
ubuntu
9 месяцев назад

A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

CVSS3: 4.3
redhat
9 месяцев назад

A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

CVSS3: 6.1
nvd
9 месяцев назад

A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

CVSS3: 6.1
debian
9 месяцев назад

A missing delay in directory upload UI could have made it possible for ...

CVSS3: 6.1
fstec
9 месяцев назад

Уязвимость браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с некорректным ограничением визуализированных слоев пользовательского интерфейса, позволяющая нарушителю провести атаку типа clickjacking («захват клика»)

EPSS

Процентиль: 37%
0.00149
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-1021