VulnerabilityModified
CVE-2017-7762
This vulnerability affects Firefox < 54.
HIGH 7.5EPSS 1.92%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.92%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing the domain of the current page. This vulnerability affects Firefox < 54.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.92% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation · mozilla/firefox
- Source
- security@mozilla.org
References
- http://www.securityfocus.com/bid/99047Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038689Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:2112Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2113Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1358248Exploit, Issue Tracking, Patch
- https://www.mozilla.org/security/advisories/mfsa2017-15/Vendor Advisory
- http://www.securityfocus.com/bid/99047Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038689Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:2112Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2113Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1358248Exploit, Issue Tracking, Patch
- https://www.mozilla.org/security/advisories/mfsa2017-15/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.