Lucene search

K
mozillaMozilla FoundationMFSA2015-49
HistoryMay 12, 2015 - 12:00 a.m.

Referrer policy ignored when links opened by middle-click and context menu — Mozilla

2015-05-1200:00:00
Mozilla Foundation
www.mozilla.org
20

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

69.6%

Security researcher Alex Verstak reported that is ignored when a link is opened through the context menu or a middle-click by mouse. This means that, in some situations, the referrer policy is ignored when opening links in new tabs and may cause some pages to open without an HTTP Referer header being set according to the author’s intended policy.

Affected configurations

Vulners
Node
mozillafirefoxRange<38
OR
mozillaseamonkeyRange<2.35

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

69.6%