CVE-2017-5381 — Path Traversal in Mozilla Firefox
Severity
7.5HIGHNVD
OSV9.8
EPSS
1.3%
top 20.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11
Latest updateMay 13
Description
The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certificate contains slashes, allowing certificate content to be saved in unsafe locations with an arbitrary filename. This vulnerability affects Firefox < 51.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages5 packages
🔴Vulnerability Details
4GHSA▶
GHSA-jw7x-8w43-2mrj: The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certificate contains slashes, allowi↗2022-05-13
OSV▶
CVE-2017-5381: The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certificate contains slashes, allowi↗2017-01-25