CVE-2017-7759Sensitive Information Exposure in Mozilla Firefox

Severity
7.5HIGHNVD
EPSS
0.3%
top 46.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the reading of local data through a violation of same-origin policy. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 54.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

CVEListV5mozilla/firefoxunspecified54
NVDmozilla/firefox< 54.0

Patches

🔴Vulnerability Details

1
GHSA
GHSA-wfjp-wqgq-35g7: Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the reading of lo2022-05-14

📋Vendor Advisories

1
Debian
CVE-2017-7759: firefox - Android intent URLs given to Firefox for Android can be used to navigate from HT...2017