Уязвимость внедрения контента и команд через кнопку панели инструментов Pocket в Mozilla Firefox
Описание
Кнопка на панели инструментов Pocket после активации отслеживает события, генерируемые её собственными страницами, но не верифицирует источник входящих событий. Это позволяет содержимому из других источников генерировать события и внедрять контент и команды в контекст Pocket. Обратите внимание, что данная проблема не затрагивает пользователей с включенной функцией e10s.
Затронутые версии ПО
- Firefox ESR версии до 45.6
- Firefox версии до 50.1
Тип уязвимости
Внедрение контента и команд
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- ExploitIssue TrackingPatch
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- ExploitIssue TrackingPatch
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Одно из
Одно из
EPSS
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
Связанные уязвимости
The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.
The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.
The Pocket toolbar button, once activated, listens for events fired fr ...
The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.
EPSS
7.5 High
CVSS3
5 Medium
CVSS2