Уязвимость спуфинга и clickjacking атак в Mozilla Firefox из-за некорректной верификации источника API-запроса в функции UITour::onPageEvent
Описание
Функция UITour::onPageEvent в Mozilla Firefox до версии 36.0 не гарантирует, что вызов API исходит из активной вкладки. Это позволяет злоумышленникам осуществлять атаки типа спуфинг и clickjacking, используя доступ к веб-сайту UI Tour.
Затронутые версии ПО
- Mozilla Firefox версии до 36.0
Тип уязвимости
- Спуфинг
- Clickjacking
Ссылки
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Issue Tracking
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Issue Tracking
Уязвимые конфигурации
Одно из
Одно из
Одно из
EPSS
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreground tab, which allows remote attackers to conduct spoofing and clickjacking attacks by leveraging access to a UI Tour web site.
The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreground tab, which allows remote attackers to conduct spoofing and clickjacking attacks by leveraging access to a UI Tour web site.
The UITour::onPageEvent function in Mozilla Firefox before 36.0 does n ...
The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreground tab, which allows remote attackers to conduct spoofing and clickjacking attacks by leveraging access to a UI Tour web site.
EPSS
4.3 Medium
CVSS2