Lucene search

K
cvelistMozillaCVELIST:CVE-2021-29974
HistoryAug 05, 2021 - 7:46 p.m.

CVE-2021-29974

2021-08-0519:46:16
mozilla
www.cve.org
1

5.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.8%

When network partitioning was enabled, e.g. as a result of Enhanced Tracking Protection settings, a TLS error page would allow the user to override an error on a domain which had specified HTTP Strict Transport Security (which implies that the error should not be override-able.) This issue did not affect the network connections, and they were correctly upgraded to HTTPS automatically. This vulnerability affects Firefox < 90.

CNA Affected

[
  {
    "product": "Firefox",
    "vendor": "Mozilla",
    "versions": [
      {
        "lessThan": "90",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

5.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.8%