Описание
When Firefox is configured to block storage of all cookies, it was still possible to store data in localstorage by using an iframe with a source of 'about:blank'. This could have led to malicious websites storing tracking data without permission. This vulnerability affects Firefox < 115.
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support |
devel | not-affected | code not present |
esm-infra/focal | DNE | |
focal | released | 115.0+build2-0ubuntu0.20.04.3 |
jammy | not-affected | code not present |
kinetic | ignored | end of life, was needs-triage |
lunar | not-affected | code not present |
trusty | ignored | end of standard support |
upstream | released | 115.0-1 |
xenial | ignored | end of standard support |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support |
devel | not-affected | |
esm-infra/focal | DNE | |
focal | not-affected | |
jammy | not-affected | |
kinetic | ignored | end of life, was needed |
lunar | not-affected | |
trusty | ignored | end of standard support |
upstream | needs-triage | |
xenial | ignored | end of standard support |
Показывать по
6.5 Medium
CVSS3
Связанные уязвимости
When Firefox is configured to block storage of all cookies, it was still possible to store data in localstorage by using an iframe with a source of 'about:blank'. This could have led to malicious websites storing tracking data without permission. This vulnerability affects Firefox < 115.
When Firefox is configured to block storage of all cookies, it was sti ...
When Firefox is configured to block storage of all cookies, it was still possible to store data in localstorage by using an iframe with a source of 'about:blank'. This could have led to malicious websites storing tracking data without permission. This vulnerability affects Firefox < 115.
Уязвимость локального хранилища (localstorage) браузера Mozilla Firefox, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Security update for MozillaFirefox, MozillaFirefox-branding-SLE
6.5 Medium
CVSS3