Описание
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | not-affected  | code not present | 
| esm-infra/focal | DNE  | |
| focal | ignored  | end of standard support, was needed | 
| jammy | not-affected  | code not present | 
| noble | not-affected  | code not present | 
| oracular | not-affected  | code not present | 
| plucky | not-affected  | code not present | 
| questing | not-affected  | code not present | 
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-apps/noble | ignored  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | ignored  | |
| noble | ignored  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| noble | ignored  | |
| oracular | ignored  | |
| plucky | ignored  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-apps/bionic | needs-triage  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-apps/focal | ignored  | |
| esm-infra/bionic | ignored  | |
| focal | ignored  | |
| jammy | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/focal | ignored  | |
| focal | ignored  | |
| jammy | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-apps/jammy | ignored  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | ignored  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | ignored  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | not-affected  | code not present | 
| esm-infra/focal | DNE  | |
| focal | ignored  | end of standard support, was needed | 
| jammy | released  | 1:128.12.0+build1-0ubuntu0.22.04.1 | 
| noble | not-affected  | code not present | 
| oracular | not-affected  | code not present | 
| plucky | not-affected  | code not present | 
| questing | not-affected  | code not present | 
| upstream | released  | 128.11 | 
Показывать по
Ссылки на источники
EPSS
4.3 Medium
CVSS3
Связанные уязвимости
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
Script elements loading cross-origin resources generated load and erro ...
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11.
Уязвимость механизма CORS браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
EPSS
4.3 Medium
CVSS3