SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-7215

The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers to bypass the Same Origin Policy by triggering use of the no-cors mode in the fetch API to attempt resource access that throws an…

MEDIUM 5.0EPSS 2.53%

Does this matter?

Lower severity and a low EPSS score (2.53%). Track it; it rarely justifies an emergency change on its own.

Description

The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers to bypass the Same Origin Policy by triggering use of the no-cors mode in the fetch API to attempt resource access that throws an exception, leading to information disclosure after a rethrow.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
2.53% probability · 84th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
fedoraproject/fedora · opensuse/leap · opensuse/opensuse · mozilla/firefox
Source
security@mozilla.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.