• CVE-2022-42927

发布时间: 2022年11月11日

修改时间: 2024年11月30日

概要

A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`.External Reference:https://www.mozilla.org/en-US/security/advisories/mfsa2022-45/#CVE-2022-42927

CVSS v3 指标

NVD openEuler
Confidentiality High
Attack Vector Network
CVSS评分 8.1 0.0
Attack Complexity Low
Privileges Required None
Scope Unchanged
Integrity High
User Interaction Required
Availability None

安全公告

公告名 概要 发布时间
KylinSec-SA-2022-2581 A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`.External Reference:https://www.mozilla.org/en-US/security/advisories/mfsa2022-45/#CVE-2022-42927 2022年11月11日

影响产品

产品 状态
KY3.4-4A firefox Unaffected
KY3.4-5 firefox Unaffected
KY3.5.1 firefox Unaffected