Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vvxh-6r52-hj35

Опубликовано: 29 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A security vulnerability in Firefox allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins. This vulnerability affects Firefox < 138 and Thunderbird < 138.

A security vulnerability in Firefox allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins. This vulnerability affects Firefox < 138 and Thunderbird < 138.

EPSS

Процентиль: 6%
0.00168
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins. This vulnerability was fixed in Firefox 138 and Thunderbird 138.

CVSS3: 5.4
redhat
больше 1 года назад

A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins. This vulnerability was fixed in Firefox 138 and Thunderbird 138.

CVSS3: 6.5
nvd
больше 1 года назад

A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins. This vulnerability was fixed in Firefox 138 and Thunderbird 138.

CVSS3: 6.5
debian
больше 1 года назад

A security vulnerability in Thunderbird allowed malicious sites to use ...

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость интерфейса Storage Access API браузера Mozilla Firefox и почтового клиента Thunderbird, позволяющая нарушителю осуществить CSRF-атаку

EPSS

Процентиль: 6%
0.00168
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352