Описание
If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Security (HSTS) will not be enabled for the connection. This vulnerability affects Firefox < 55.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 55.0.2+build1-0ubuntu4 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [55.0.1+build2-0ubuntu0.14.04.2]] |
| precise/esm | DNE | |
| trusty | released | 55.0.1+build2-0ubuntu0.14.04.2 |
| trusty/esm | DNE | trusty was released [55.0.1+build2-0ubuntu0.14.04.2] |
| upstream | released | 55.0 |
| vivid/ubuntu-core | DNE | |
| xenial | released | 55.0.1+build2-0ubuntu0.16.04.2 |
| yakkety | ignored | end of life |
| zesty | released | 55.0.1+build2-0ubuntu0.17.04.2 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | |
| esm-infra-legacy/trusty | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE | |
| upstream | needs-triage | |
| vivid/ubuntu-core | DNE | |
| xenial | DNE | |
| yakkety | DNE | |
| zesty | not-affected |
Показывать по
EPSS
5 Medium
CVSS2
5.3 Medium
CVSS3
Связанные уязвимости
If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Security (HSTS) will not be enabled for the connection. This vulnerability affects Firefox < 55.
If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Security (HSTS) will not be enabled for the connection. This vulnerability affects Firefox < 55.
If a server sends two Strict-Transport-Security (STS) headers for a si ...
If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Security (HSTS) will not be enabled for the connection. This vulnerability affects Firefox < 55.
Уязвимость реализации механизма Strict Transport Security (HSTS) браузера Mozilla Firefox, позволяющая нарушителю оказать воздействие на целостность данных
EPSS
5 Medium
CVSS2
5.3 Medium
CVSS3