Уязвимость утечки информации о посещённых веб-сайтах в Mozilla Firefox через комбинацию Content Security Policy и перенаправления HTTP на HTTPS
Описание
Злоумышленник может использовать комбинацию политики безопасности контента (Content Security Policy) и перенаправление HTTP на HTTPS для проверки того, находится ли известный сайт в истории браузера пользователя.
Затронутые версии ПО
- Mozilla Firefox версий ниже 50
Тип уязвимости
Утечка информации
Ссылки
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Issue TrackingVendor Advisory
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Issue TrackingVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
EPSS
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
Связанные уязвимости
Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's browser history. This vulnerability affects Firefox < 50.
Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's browser history. This vulnerability affects Firefox < 50.
Content Security Policy combined with HTTP to HTTPS redirection can be ...
Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's browser history. This vulnerability affects Firefox < 50.
EPSS
5.3 Medium
CVSS3
5 Medium
CVSS2