PT-2018-3985 · Mozilla+3 · Firefox+3
Andrey
·
Publicado
2018-08-15
·
Atualizado
2024-12-12
·
CVE-2019-11725
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 68
Description
The issue is related to shortcomings in the authorization procedure of the Firefox web browser. It may allow a remote attacker to compromise data integrity. When a user visits a site marked as unsafe by the Safebrowsing API, warning messages are displayed, but resources from the same site loaded through websockets are not blocked, leading to the loading of unsafe resources and bypassing safebrowsing protections.
Recommendations
For Firefox versions prior to 68, update to version 68 or later to resolve the issue. As a temporary workaround, consider restricting the use of websockets for sites marked as unsafe by the Safebrowsing API until a patch is available. Avoid using websockets to load resources from potentially unsafe sites until the issue is resolved.
Correção
Improper Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Firefox
Suse
Ubuntu