PT-2017-3676 · Mozilla+2 · Firefox+2

Jerry Decime

·

Publicado

2017-10-17

·

Atualizado

2024-12-12

·

CVE-2018-5115

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Mozilla Firefox versions prior to 58
Description: The issue is related to an authentication error in Mozilla Firefox when handling HTTP requests. This can lead to user confusion about the origin of an authentication request, potentially causing users to send private credentials to a third-party site. The problem arises when an HTTP authentication prompt is triggered by a background network request and is displayed over the currently loaded page, making it difficult for users to identify the real domain making the request.
Recommendations: For versions prior to 58, update to version 58 or later to resolve the issue. As a temporary workaround, consider being cautious when encountering HTTP authentication prompts, especially if they appear over a foreground page, and verify the domain making the request to avoid sending credentials to unauthorized sites.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1178
ALT-PU-2018-1854
BDU:2018-00867
CVE-2018-5115
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
USN-3544-1
USN-3544-2

Produtos afetados

Alt Linux
Firefox
Ubuntu