Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-29974
HistoryAug 05, 2021 - 8:15 p.m.

Design/Logic Flaw

2021-08-0520:15:00
PRIOn knowledge base
www.prio-n.com
2

4.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.8%

When network partitioning was enabled, e.g. as a result of Enhanced Tracking Protection settings, a TLS error page would allow the user to override an error on a domain which had specified HTTP Strict Transport Security (which implies that the error should not be override-able.) This issue did not affect the network connections, and they were correctly upgraded to HTTPS automatically. This vulnerability affects Firefox < 90.

CPENameOperatorVersion
firefoxlt90.0

4.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.8%