Описание
Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Ссылки
- Permissions Required
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 153.1.0 (исключая)Версия до 154.0.0 (исключая)Версия до 153.1.0 (исключая)Версия до 154.0 (исключая)
Одно из
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
EPSS
Процентиль: 20%
0.00283
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-843
Связанные уязвимости
CVSS3: 9.1
ubuntu
9 дней назад
(Same-origin policy bypass in the DOM: Service Workers component. This ...)
CVSS3: 6.1
redhat
10 дней назад
Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
CVSS3: 9.1
debian
10 дней назад
Same-origin policy bypass in the DOM: Service Workers component. This ...
CVSS3: 9.1
github
9 дней назад
Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
EPSS
Процентиль: 20%
0.00283
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-843