PT-2015-7474 · Mozilla+3 · Firefox+3
Abdulrahman Alqabandi
·
Published
2015-10-15
·
Updated
2024-12-12
·
CVE-2015-7184
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 41.0.2
Description
The issue concerns the implementation of the
fetch API in Mozilla Firefox, where access to the HTTP response body is not properly restricted in certain situations. This occurs when user credentials are supplied, but the CORS cross-origin request algorithm is not followed correctly. As a result, remote attackers can bypass the Same Origin Policy by manipulating a website.Recommendations
For versions prior to 41.0.2, update to version 41.0.2 or later to resolve the issue.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Firefox
Suse
Ubuntu