Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-6427

Опубликовано: 24 июн. 2025
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

An attacker was able to bypass the connect-src directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
Версия до 140.0 (исключая)

EPSS

Процентиль: 22%
0.003
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-693

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 1 года назад

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140 and Thunderbird < 140.

CVSS3: 6.1
redhat
около 1 года назад

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

CVSS3: 9.1
debian
около 1 года назад

An attacker was able to bypass the `connect-src` directive of a Conten ...

CVSS3: 9.1
github
около 1 года назад

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140.

CVSS3: 9.1
fstec
около 1 года назад

Уязвимость механизма Content Security Policy (CSP) браузера Mozilla Firefox, позволяющая нарушителю обойти ограничения безопасности и получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 22%
0.003
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-693