Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-7762

Опубликовано: 20 апр. 2017
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing the domain of the current page. This vulnerability affects Firefox < 54.

Отчет

Red Hat Product Security has rated this issue as having a security impact of Moderate, and a future update may address this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6thunderbirdNot affected
Red Hat Enterprise Linux 7thunderbirdNot affected
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 8thunderbirdNot affected
Red Hat Enterprise Linux 6firefoxFixedRHSA-2018:211228.06.2018
Red Hat Enterprise Linux 7firefoxFixedRHSA-2018:211328.06.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-290
https://bugzilla.redhat.com/show_bug.cgi?id=1590493Mozilla: address bar username and password spoofing in reader mode

EPSS

Процентиль: 67%
0.0054
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing the domain of the current page. This vulnerability affects Firefox < 54.

CVSS3: 7.5
nvd
больше 7 лет назад

When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing the domain of the current page. This vulnerability affects Firefox < 54.

CVSS3: 7.5
debian
больше 7 лет назад

When entered directly, Reader Mode did not strip the username and pass ...

CVSS3: 7.5
github
больше 3 лет назад

When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing the domain of the current page. This vulnerability affects Firefox < 54.

oracle-oval
больше 7 лет назад

ELSA-2018-2113: firefox security update (CRITICAL)

EPSS

Процентиль: 67%
0.0054
Низкий

7.5 High

CVSS3