Lucene search

K
mozillaMozilla FoundationMFSA2009-30
HistoryJun 11, 2009 - 12:00 a.m.

Incorrect principal set for file: resources loaded via location bar — Mozilla

2009-06-1100:00:00
Mozilla Foundation
www.mozilla.org
18

CVSS2

5.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:C/I:N/A:N

EPSS

0.017

Percentile

87.8%

Security researchers Adam Barth and Collin Jackson reported that when a file: resource is loaded via the location bar it inherits the principal of the previously loaded document. This vulnerability can potentially give the newly loaded document additional privileges to access the contents of other local files that it wouldn’t otherwise have permission to read.

Affected configurations

Vulners
Node
mozillafirefoxRange<3.0.11
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

CVSS2

5.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:C/I:N/A:N

EPSS

0.017

Percentile

87.8%