Lucene search

K
cve[email protected]CVE-2015-2711
HistoryMay 14, 2015 - 10:59 a.m.

CVE-2015-2711

2015-05-1410:59:04
CWE-200
web.nvd.nist.gov
45
mozilla
firefox
cve-2015-2711
security
referrer policy
sensitive information

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

8.8

Confidence

High

EPSS

0.003

Percentile

69.6%

Mozilla Firefox before 38.0 does not recognize a referrer policy delivered by a referrer META element in cases of context-menu navigation and middle-click navigation, which allows remote attackers to obtain sensitive information by reading web-server Referer logs that contain private data in a URL, as demonstrated by a private path component.

Affected configurations

NVD
Node
opensuseopensuseMatch13.1
OR
opensuseopensuseMatch13.2
Node
mozillafirefoxRange37.0.2
VendorProductVersionCPE
opensuseopensuse13.1cpe:/o:opensuse:opensuse:13.1:::
opensuseopensuse13.2cpe:/o:opensuse:opensuse:13.2:::

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

8.8

Confidence

High

EPSS

0.003

Percentile

69.6%