Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27167
HistorySep 21, 2020 - 6:39 a.m.

Sandbox Bypass

2020-09-2106:39:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.004 Low

EPSS

Percentile

72.9%

firefox is vulnerable to sandbox bypass. Until explicitly accessed by script, window.global.This is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames (window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed.