Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-29971

Опубликовано: 05 авг. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port - would be granted that permission. This bug only affects Firefox for Android. Other operating systems are unaffected.. This vulnerability affects Firefox < 90.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:android:*:*
Версия до 90.0 (исключая)

EPSS

Процентиль: 61%
0.00412
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-281

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port - would be granted that permission. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 90.

CVSS3: 9.8
debian
больше 4 лет назад

If a user had granted a permission to a webpage and saved that grant, ...

github
больше 3 лет назад

If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port - would be granted that permission. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 90.

CVSS3: 5.4
fstec
больше 4 лет назад

Уязвимость браузера Mozilla Firefox для Android, связанная с недостатками разграничения доступа, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 61%
0.00412
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-281