Lucene search

K
cvelistMozillaCVELIST:CVE-2021-43540
HistoryDec 08, 2021 - 9:20 p.m.

CVE-2021-43540

2021-12-0821:20:08
mozilla
www.cve.org
3

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.2%

WebExtensions with the correct permissions were able to create and install ServiceWorkers for third-party websites that would not have been uninstalled with the extension. This vulnerability affects Firefox < 95.

CNA Affected

[
  {
    "product": "Firefox",
    "vendor": "Mozilla",
    "versions": [
      {
        "lessThan": "95",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.2%