SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-7762

This vulnerability affects Firefox < 54.

HIGH 7.5EPSS 1.92%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.92%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing the domain of the current page. This vulnerability affects Firefox < 54.

CVSS 3.0
7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
1.92% probability · 79th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation · mozilla/firefox
Source
security@mozilla.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.