CVE-2014-4671

Severity
4.3MEDIUM
EPSS
35.8%
top 2.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 9
Latest updateAug 31

Description

Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages5 packages

NVDadobe/flash_player11.2.202.378+33
NVDadobe/adobe_air14.0.0.110+2
NVDadobe/adobe_air_sdk14.0.0.110+2
Ubuntuflashplugin-nonfree< 11.2.202.394ubuntu0.14.04.1
npmhapi< 6.1.0

🔴Vulnerability Details

4
GHSA
Rosetta-Flash JSONP Vulnerability in hapi2020-08-31
OSV
Rosetta-Flash JSONP Vulnerability in hapi2020-08-31
CVEList
CVE-2014-4671: Adobe Flash Player before 132014-07-09
OSV
CVE-2014-4671: Adobe Flash Player before 132014-07-09

🔍Detection Rules

4
Suricata
ET WEB_SERVER Adobe Flash Player Rosetta Flash compressed CWS in URI2014-07-18
Suricata
ET WEB_CLIENT Adobe Flash Player Rosetta Flash compressed CWS2014-07-09
Suricata
ET WEB_CLIENT Adobe Flash Player Rosetta Flash compressed ZWS2014-07-09
Suricata
ET WEB_CLIENT Adobe Flash Player Rosetta Flash compressed FWS2014-07-09

📋Vendor Advisories

2
Red Hat
flash-plugin: information leaks and hardening bypass fixed in APSB15-232015-09-21
Red Hat
flash-plugin: vulnerable JSONP callback APIs issue (APSB14-17)2014-07-08

💬Community

1
Bugzilla
CVE-2014-4671 flash-plugin: vulnerable JSONP callback APIs issue (APSB14-17)2014-07-09
CVE-2014-4671 (MEDIUM CVSS 4.3) | Adobe Flash Player before 13.0.0.23 | cvebase.io