PT-2015-1043 · Mozilla+5 · Firefox+7

Muneaki Nishimura

·

Published

2015-03-31

·

Updated

2024-12-12

·

CVE-2015-0807

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 37.0 Mozilla Firefox ESR versions prior to 31.6 Thunderbird versions prior to 31.6
Description The issue is related to the navigator.sendBeacon function and its handling of HTTP 30x status codes. This allows a remote attacker to bypass CORS access-control checks and conduct cross-site request forgery attacks using a specially crafted web site. The exploitation of this issue enables an attacker to circumvent intended security controls, potentially leading to unauthorized actions on behalf of the user.
Recommendations For Mozilla Firefox versions prior to 37.0, update to version 37.0 or later to resolve the issue. For Mozilla Firefox ESR versions prior to 31.6, update to version 31.6 or later to resolve the issue. For Thunderbird versions prior to 31.6, update to version 31.6 or later to resolve the issue. As a temporary workaround, consider disabling the navigator.sendBeacon function until a patch is available. Restrict access to sensitive resources to minimize the risk of exploitation. Avoid using the navigator.sendBeacon function in scenarios where CORS checks are crucial until the issue is resolved.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1374
ALT-PU-2015-1464
ALT-PU-2015-1584
BDU:2015-09893
BDU:2015-09894
BDU:2015-09895
CESA-2015_0766
CESA-2015_0771
CVE-2015-0807
DSA-3211-1
DSA-3212-1
MGASA-2015-0131
MGASA-2015-0342
OPENSUSE-SU-2015_0677-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:10230-1
OPENSUSE-SU-2024:14572-1
RHSA-2015:0766
RHSA-2015:0771
RHSA-2015_0766
RHSA-2015_0771
SUSE-SU-2015:0704-1
SUSE-SU-2015:0704-2
USN-2550-1
USN-2552-1

Affected Products

Alt Linux
Centos
Firefox
Firefox Esr
Red Hat
Suse
Thunderbird
Ubuntu