Описание
Permission prompts for opening external schemes were only shown for ContentPrincipals resulting in extensions being able to open them without user interaction via ExpandedPrincipals. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | released  | 110.0+build3-0ubuntu0.18.04.1 | 
| devel | not-affected  | code not present | 
| esm-infra/focal | DNE  | |
| focal | released  | 110.0+build3-0ubuntu0.20.04.1 | 
| jammy | not-affected  | code not present | 
| kinetic | not-affected  | code not present | 
| lunar | not-affected  | code not present | 
| mantic | not-affected  | code not present | 
| noble | not-affected  | code not present | 
| trusty | ignored  | end of standard support | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | ignored  | end of standard support, was needs-triage | 
| esm-apps/bionic | ignored  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| kinetic | DNE  | |
| trusty | DNE  | |
| upstream | ignored  | |
| xenial | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | ignored  | end of standard support, was needs-triage | 
| esm-apps/focal | ignored  | |
| esm-infra/bionic | ignored  | |
| focal | ignored  | |
| jammy | DNE  | |
| kinetic | DNE  | |
| trusty | DNE  | |
| upstream | ignored  | |
| xenial | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| esm-infra/focal | ignored  | |
| focal | ignored  | |
| jammy | DNE  | |
| kinetic | DNE  | |
| trusty | DNE  | |
| upstream | ignored  | |
| xenial | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-apps/jammy | ignored  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | ignored  | |
| kinetic | ignored  | end of life, was needs-triage | 
| lunar | ignored  | end of life, was needs-triage | 
| mantic | DNE  | |
| noble | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | ignored  | |
| kinetic | DNE  | |
| trusty | DNE  | |
| upstream | ignored  | |
| xenial | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | released  | 1:102.8.0+build2-0ubuntu0.18.04.1 | 
| devel | not-affected  | 1:102.10.0+build2-0ubuntu1 | 
| esm-infra/focal | DNE  | |
| focal | released  | 1:102.8.0+build2-0ubuntu0.20.04.1 | 
| jammy | released  | 1:102.8.0+build2-0ubuntu0.22.04.1 | 
| kinetic | released  | 1:102.8.0+build2-0ubuntu0.22.10.1 | 
| lunar | not-affected  | 1:102.10.0+build2-0ubuntu1 | 
| mantic | not-affected  | 1:102.10.0+build2-0ubuntu1 | 
| noble | not-affected  | 1:102.10.0+build2-0ubuntu1 | 
| trusty | ignored  | end of standard support | 
Показывать по
Ссылки на источники
EPSS
8.8 High
CVSS3
Связанные уязвимости
Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them without user interaction via <code>ExpandedPrincipals</code>. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them without user interaction via <code>ExpandedPrincipals</code>. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Permission prompts for opening external schemes were only shown for <c ...
Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them without user interaction via <code>ExpandedPrincipals</code>. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Уязвимость браузеров Mozilla Firefox, Mozilla Firefox ESR, почтового клиента Mozilla Thunderbird, связанная с неправильной нейтрализаций закодированных схем URI на веб-странице, позволяющая нарушителю загрузить файлы или взаимодействовать с программным обеспечением, уже установленным в системе
EPSS
8.8 High
CVSS3