Описание
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 74.0+build3-0ubuntu0.18.04.1 |
devel | released | 74.0+build3-0ubuntu1 |
eoan | released | 74.0+build3-0ubuntu0.19.10.1 |
esm-infra-legacy/trusty | DNE | |
esm-infra/focal | DNE | |
focal | released | 74.0+build3-0ubuntu1 |
groovy | released | 74.0+build3-0ubuntu1 |
hirsute | released | 74.0+build3-0ubuntu1 |
impish | released | 74.0+build3-0ubuntu1 |
jammy | released | 74.0+build3-0ubuntu1 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support, was needs-triage |
devel | DNE | |
eoan | DNE | |
esm-apps/bionic | ignored | |
esm-infra-legacy/trusty | DNE | |
esm-infra/focal | DNE | |
focal | DNE | |
groovy | DNE | |
hirsute | DNE | |
impish | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support, was needs-triage |
devel | DNE | |
eoan | ignored | end of life |
esm-apps/focal | ignored | |
esm-infra-legacy/trusty | DNE | |
esm-infra/bionic | ignored | |
focal | ignored | |
groovy | ignored | end of life |
hirsute | DNE | |
impish | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
devel | DNE | |
eoan | ignored | end of life |
esm-infra-legacy/trusty | DNE | |
esm-infra/focal | DNE | |
focal | DNE | |
groovy | DNE | |
hirsute | DNE | |
impish | DNE | |
jammy | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 1:68.7.0+build1-0ubuntu0.18.04.1 |
devel | released | 1:68.6.0+build2-0ubuntu1 |
eoan | released | 1:68.7.0+build1-0ubuntu0.19.10.1 |
esm-infra-legacy/trusty | DNE | |
esm-infra/focal | DNE | |
focal | released | 1:68.6.0+build2-0ubuntu1 |
groovy | released | 1:68.6.0+build2-0ubuntu1 |
hirsute | released | 1:68.6.0+build2-0ubuntu1 |
impish | released | 1:68.6.0+build2-0ubuntu1 |
jammy | released | 1:68.6.0+build2-0ubuntu1 |
Показывать по
Ссылки на источники
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3
Связанные уязвимости
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
The 'Copy as cURL' feature of Devtools' network tab did not properly e ...
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3