Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-7789

Опубликовано: 11 июн. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 5.3

Описание

If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Security (HSTS) will not be enabled for the connection. This vulnerability affects Firefox < 55.

РелизСтатусПримечание
devel

released

55.0.2+build1-0ubuntu4
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [55.0.1+build2-0ubuntu0.14.04.2]]
precise/esm

DNE

trusty

released

55.0.1+build2-0ubuntu0.14.04.2
trusty/esm

DNE

trusty was released [55.0.1+build2-0ubuntu0.14.04.2]
upstream

released

55.0
vivid/ubuntu-core

DNE

xenial

released

55.0.1+build2-0ubuntu0.16.04.2
yakkety

ignored

end of life
zesty

released

55.0.1+build2-0ubuntu0.17.04.2

Показывать по

РелизСтатусПримечание
devel

not-affected

esm-infra-legacy/trusty

DNE

precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

needs-triage

vivid/ubuntu-core

DNE

xenial

DNE

yakkety

DNE

zesty

not-affected

Показывать по

EPSS

Процентиль: 73%
0.00769
Низкий

5 Medium

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
больше 8 лет назад

If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Security (HSTS) will not be enabled for the connection. This vulnerability affects Firefox < 55.

CVSS3: 5.3
nvd
больше 7 лет назад

If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Security (HSTS) will not be enabled for the connection. This vulnerability affects Firefox < 55.

CVSS3: 5.3
debian
больше 7 лет назад

If a server sends two Strict-Transport-Security (STS) headers for a si ...

CVSS3: 5.3
github
больше 3 лет назад

If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Security (HSTS) will not be enabled for the connection. This vulnerability affects Firefox < 55.

CVSS3: 5.3
fstec
больше 11 лет назад

Уязвимость реализации механизма Strict Transport Security (HSTS) браузера Mozilla Firefox, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 73%
0.00769
Низкий

5 Medium

CVSS2

5.3 Medium

CVSS3