Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-6427

Опубликовано: 24 июн. 2025
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

An attacker was able to bypass the connect-src directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
Версия до 140.0 (исключая)

EPSS

Процентиль: 18%
0.00057
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-693

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 1 месяца назад

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140.

CVSS3: 6.1
redhat
около 1 месяца назад

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140.

CVSS3: 9.1
debian
около 1 месяца назад

An attacker was able to bypass the `connect-src` directive of a Conten ...

CVSS3: 9.1
github
около 1 месяца назад

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140.

CVSS3: 9.1
fstec
около 1 месяца назад

Уязвимость механизма Content Security Policy (CSP) браузера Mozilla Firefox, позволяющая нарушителю обойти ограничения безопасности и получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 18%
0.00057
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-693