Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-0748

Опубликовано: 23 янв. 2024
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar or history. This vulnerability affects Firefox < 122.

A vulnerability was found in Firefox due to a compromised content process updating the document URI. This flaw allows an attacker to set an arbitrary URI in the address bar or history.

Отчет

This vulnerability only affects Non ESR versions of Firefox and we don't ship Non ESR.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6firefoxNot affected
Red Hat Enterprise Linux 7firefoxNot affected
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 8firefox:flatpak/firefoxNot affected
Red Hat Enterprise Linux 9firefoxNot affected
Red Hat Enterprise Linux 9firefox:flatpak/firefoxNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2260016firefox: an arbitrary URI in the address bar or history

EPSS

Процентиль: 44%
0.00213
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 1 года назад

A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar or history. This vulnerability affects Firefox < 122.

CVSS3: 4.3
nvd
больше 1 года назад

A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar or history. This vulnerability affects Firefox < 122.

CVSS3: 4.3
debian
больше 1 года назад

A compromised content process could have updated the document URI. Thi ...

CVSS3: 4.3
github
больше 1 года назад

A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar or history. This vulnerability affects Firefox < 122.

CVSS3: 4.3
fstec
больше 1 года назад

Уязвимость браузера Mozilla Firefox, связанная с недостатками разграничения доступа, позволяющая нарушителю установить произвольный URI в адресной строке или истории браузера

EPSS

Процентиль: 44%
0.00213
Низкий

4.3 Medium

CVSS3