发布时间: 2022年11月11日
修改时间: 2024年11月30日
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`.External Reference:https://www.mozilla.org/en-US/security/advisories/mfsa2022-45/#CVE-2022-42927
NVD | openEuler | |
---|---|---|
Confidentiality | High | |
Attack Vector | Network | |
CVSS评分 | 8.1 | 0.0 |
Attack Complexity | Low | |
Privileges Required | None | |
Scope | Unchanged | |
Integrity | High | |
User Interaction | Required | |
Availability | None |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2022-2581 | A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`.External Reference:https://www.mozilla.org/en-US/security/advisories/mfsa2022-45/#CVE-2022-42927 | 2022年11月11日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | firefox | Unaffected |
KY3.4-5 | firefox | Unaffected |
KY3.5.1 | firefox | Unaffected |