Lucene search

K
mozillaMozilla FoundationMFSA2012-59
HistoryAug 28, 2012 - 12:00 a.m.

Location object can be shadowed using Object.defineProperty — Mozilla

2012-08-2800:00:00
Mozilla Foundation
www.mozilla.org
26

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.003 Low

EPSS

Percentile

71.3%

Security researcher Mariusz Mlynski reported that it is possible to shadow the location object using Object.defineProperty. This could be used to confuse the current location to plugins, allowing for possible cross-site scripting (XSS) attacks.

Affected configurations

Vulners
Node
mozillafirefoxRange<15
OR
mozillafirefox_esrRange<10.0.8
OR
mozillaseamonkeyRange<2.12
OR
mozillathunderbirdRange<15
OR
mozillathunderbird_esrRange<10.0.8

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.003 Low

EPSS

Percentile

71.3%