Описание
A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the origin. This results in a cross-origin information leak of this path information. This vulnerability affects Firefox < 55.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | released | 55.0.2+build1-0ubuntu4 |
| bionic | released | 55.0.2+build1-0ubuntu4 |
| cosmic | released | 55.0.2+build1-0ubuntu4 |
| devel | released | 55.0.2+build1-0ubuntu4 |
| disco | released | 55.0.2+build1-0ubuntu4 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [55.0.1+build2-0ubuntu0.14.04.2]] |
| precise/esm | DNE | |
| trusty | released | 55.0.1+build2-0ubuntu0.14.04.2 |
| trusty/esm | DNE | trusty was released [55.0.1+build2-0ubuntu0.14.04.2] |
| upstream | released | 55.0 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | not-affected | code not present |
| cosmic | DNE | |
| devel | DNE | |
| disco | DNE | |
| esm-apps/bionic | not-affected | code not present |
| esm-infra-legacy/trusty | DNE | |
| precise/esm | DNE | |
| trusty | DNE | |
| trusty/esm | DNE |
Показывать по
EPSS
5 Medium
CVSS2
5.3 Medium
CVSS3
Связанные уязвимости
A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the origin. This results in a cross-origin information leak of this path information. This vulnerability affects Firefox < 55.
A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the origin. This results in a cross-origin information leak of this path information. This vulnerability affects Firefox < 55.
A content security policy (CSP) "frame-ancestors" directive containing ...
A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the origin. This results in a cross-origin information leak of this path information. This vulnerability affects Firefox < 55.
Уязвимость реализации механизма CSP (Content Security Policy) браузера Mozilla Firefox, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
EPSS
5 Medium
CVSS2
5.3 Medium
CVSS3