CVE-2017-7762

Impact:
Moderate
Public Date:
2017-04-20
CWE:
CWE-290
Bugzilla:
1590493: CVE-2017-7762 Mozilla: address bar username and password spoofing in reader mode

The MITRE CVE dictionary describes this issue as:

When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing the domain of the current page. This vulnerability affects Firefox < 54.

Find out more about CVE-2017-7762 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Red Hat Product Security has rated this issue as having a security impact of Moderate, and a future update may address this flaw.

CVSS v3 metrics

CVSS3 Base Score 6.1
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Changed
Confidentiality Low
Integrity Impact Low
Availability Impact None

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 7 (firefox) RHSA-2018:2113 2018-06-28
Red Hat Enterprise Linux 6 (firefox) RHSA-2018:2112 2018-06-28

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 7 thunderbird Not affected
Red Hat Enterprise Linux 6 thunderbird Not affected

External References

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.