[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

HSTS errors could be overridden when network partitioning was enabled - CVE-2021-29974

ID: oval:org.secpod.oval:def:73937Date: (C)2021-07-16   (M)2023-11-19
Class: VULNERABILITYFamily: macos




Mozilla Firefox 90 : When network partitioning was enabled, e.g. as a result of Enhanced Tracking Protection settings, a TLS error page would allow the user to override an error on a domain which had specified HTTP Strict Transport Security (which implies that the error should not be override-able.) This issue did not affect the network connections, and they were correctly upgraded to HTTPS automatically.

Platform:
Apple Mac OS 14
Apple Mac OS 13
Apple Mac OS 12
Apple Mac OS X 10.9
Apple Mac OS X 10.10
Apple Mac OS X 10.11
Apple Mac OS X 10.12
Apple Mac OS X 10.13
Apple Mac OS X 10.14
Apple Mac OS X 10.15
Apple Mac OS 11
Product:
Mozilla Firefox
Reference:
CVE-2021-29974
CVE    1
CVE-2021-29974

© SecPod Technologies