Описание
Regular expressions used to filter out forbidden properties and values from style directives in calls to console.log
weren't accounting for external URLs. Data could then be potentially exfiltrated from the browser. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7.
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 109.0+build2-0ubuntu0.18.04.1 |
devel | not-affected | code not present |
esm-infra/focal | DNE | |
focal | released | 109.0+build2-0ubuntu0.20.04.1 |
jammy | not-affected | code not present |
kinetic | not-affected | code not present |
lunar | not-affected | code not present |
mantic | not-affected | code not present |
noble | not-affected | code not present |
trusty | ignored | end of standard support |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support, was needs-triage |
esm-apps/bionic | ignored | |
esm-infra/focal | DNE | |
focal | DNE | |
jammy | DNE | |
kinetic | DNE | |
trusty | DNE | |
upstream | ignored | |
xenial | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support, was needs-triage |
esm-apps/focal | ignored | |
esm-infra/bionic | ignored | |
focal | ignored | |
jammy | DNE | |
kinetic | DNE | |
trusty | DNE | |
upstream | ignored | |
xenial | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
esm-infra/focal | ignored | |
focal | ignored | |
jammy | DNE | |
kinetic | DNE | |
trusty | DNE | |
upstream | ignored | |
xenial | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
devel | DNE | |
esm-apps/jammy | ignored | |
esm-infra/focal | DNE | |
focal | DNE | |
jammy | ignored | |
kinetic | ignored | end of life, was needs-triage |
lunar | ignored | end of life, was needs-triage |
mantic | DNE | |
noble | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
esm-infra/focal | DNE | |
focal | DNE | |
jammy | ignored | |
kinetic | DNE | |
trusty | DNE | |
upstream | ignored | |
xenial | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 1:102.7.1+build2-0ubuntu0.18.04.1 |
devel | released | 1:102.7.1+build2-0ubuntu1 |
esm-infra/focal | DNE | |
focal | released | 1:102.7.1+build2-0ubuntu0.20.04.1 |
jammy | released | 1:102.7.1+build2-0ubuntu0.22.04.1 |
kinetic | released | 1:102.7.1+build2-0ubuntu0.22.10.1 |
lunar | released | 1:102.7.1+build2-0ubuntu1 |
mantic | released | 1:102.7.1+build2-0ubuntu1 |
noble | released | 1:102.7.1+build2-0ubuntu1 |
trusty | ignored | end of standard support |
Показывать по
Ссылки на источники
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Regular expressions used to filter out forbidden properties and values from style directives in calls to <code>console.log</code> weren't accounting for external URLs. Data could then be potentially exfiltrated from the browser. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7.
Regular expressions used to filter out forbidden properties and values from style directives in calls to <code>console.log</code> weren't accounting for external URLs. Data could then be potentially exfiltrated from the browser. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7.
Regular expressions used to filter out forbidden properties and values ...
Regular expressions used to filter out forbidden properties and values from style directives in calls to <code>console.log</code> weren't accounting for external URLs. Data could then be potentially exfiltrated from the browser. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7.
Уязвимость веб-браузеров Firefox, Firefox ESR, почтового клиента Thunderbird, связанная с недостаточной обработкой регулярных выражений, позволяющая нарушителю получить доступ к конфиденциальным данным
EPSS
6.5 Medium
CVSS3