Уязвимость подмены отображаемого сайта в диалоговом окне загрузки файлов через открытое перенаправление в Firefox и Thunderbird
Описание
Злоумышленник эксплуатирует уязвимость открытого перенаправления (Open Redirect) на веб-сайте для подмены отображаемого сайта в диалоговом окне загрузки файлов. Это позволяет показывать оригинальный сайт (страдающий от открытого перенаправления), вместо реального сайта, с которого загружается файл.
Затронутые версии ПО
- Firefox версии ниже 81
- Thunderbird версии ниже 78.3
- Firefox ESR версии ниже 78.3
Тип уязвимости
Подмена сайта через открытое перенаправление (Open Redirect)
Ссылки
- Broken LinkMailing ListThird Party Advisory
- Broken LinkMailing ListThird Party Advisory
- Issue TrackingPermissions RequiredVendor Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Broken LinkMailing ListThird Party Advisory
- Broken LinkMailing ListThird Party Advisory
- Issue TrackingPermissions RequiredVendor Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Одно из
Одно из
Одно из
EPSS
6.1 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
Связанные уязвимости
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
By exploiting an Open Redirect vulnerability on a website, an attacker ...
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
EPSS
6.1 Medium
CVSS3
5.8 Medium
CVSS2