Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37374
HistoryOct 01, 2022 - 6:51 p.m.

Authentication Bypass

2022-10-0118:51:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
firefox
authentication bypass
vulnerability
featurepolicy
attacker
device permissions
sub documents
software

0.001 Low

EPSS

Percentile

45.3%

firefox is vulnerable to authentication bypass. The vulnerability exists because certain pages do not have their FeaturePolicy fully initialized which allows an attacker to bypass the leaked device permissions into untrusted sub documents.