Описание
An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme and a timeout race condition. This vulnerability affects Focus for iOS < 122.
Ссылки
- Issue Tracking
- Vendor Advisory
- Issue Tracking
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 122.0 (исключая)
cpe:2.3:a:mozilla:firefox_focus:*:*:*:*:*:iphone_os:*:*
EPSS
Процентиль: 55%
0.00323
Низкий
8.1 High
CVSS3
Дефекты
CWE-367
CWE-367
Связанные уязвимости
CVSS3: 8.1
github
почти 2 года назад
An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme and a timeout race condition. This vulnerability affects Focus for iOS < 122.
EPSS
Процентиль: 55%
0.00323
Низкий
8.1 High
CVSS3
Дефекты
CWE-367
CWE-367