[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253390

 
 

909

 
 

197257

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Web Extensions could access pre-redirect URL when their context menu was triggered by a user - CVE-2021-43531

ID: oval:org.secpod.oval:def:99794Date: (C)2024-05-08   (M)2024-05-08
Class: VULNERABILITYFamily: macos




Mozilla Firefox 94 : When a user loaded a Web Extensions context menu, the Web Extension could access the post-redirect URL of the element clicked. If the Web Extension lacked the WebRequest permission for the hosts involved in the redirect, this would be a same-origin-violation leaking data the Web Extension should have access to.

Platform:
Apple Mac OS 14
Apple Mac OS 13
Apple Mac OS 12
Apple Mac OS X 10.11
Apple Mac OS X 10.12
Apple Mac OS X 10.13
Apple Mac OS X 10.14
Apple Mac OS X 10.15
Apple Mac OS 11
Product:
Mozilla Firefox
Reference:
CVE-2021-43531
CVE    1
CVE-2021-43531

© SecPod Technologies