CVE-2017-7789Improper Authorization in Mozilla Firefox

Severity
5.3MEDIUMNVD
OSV9.1
EPSS
0.8%
top 26.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 13

Description

If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Security (HSTS) will not be enabled for the connection. This vulnerability affects Firefox < 55.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

debiandebian/firefox< firefox 55.0-1 (sid)
CVEListV5mozilla/firefoxunspecified55
NVDmozilla/firefox< 55.0
Ubuntumozilla/firefox< 55.0.1+build2-0ubuntu0.14.04.2+3

🔴Vulnerability Details

5
GHSA
GHSA-9564-97j4-99c4: If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Secu2022-05-13
OSV
firefox regression2017-08-17
OSV
ubufox update2017-08-16
OSV
firefox vulnerabilities2017-08-15
OSV
CVE-2017-7789: If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Secu2017-07-04

📋Vendor Advisories

5
Ubuntu
Firefox regression2017-08-17
Ubuntu
Ubufox update2017-08-16
Ubuntu
Firefox vulnerabilities2017-08-15
Red Hat
Mozilla: Failure to enable HSTS when two STS headers are sent for a connection (MFSA 2017-18)2017-08-08
Debian
CVE-2017-7789: firefox - If a server sends two Strict-Transport-Security (STS) headers for a single conne...2017

💬Community

1
Bugzilla
CVE-2017-7789 Mozilla: Failure to enable HSTS when two STS headers are sent for a connection (MFSA 2017-18)2017-08-08