CVE-2015-0807

CVSS v2.0 6.8 (Medium)
68% Progress
EPSS 0.33 % (72th)
0.33% Progress
Affected Products 3
Advisories 13

The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x status codes for redirects after a preflight request has occurred, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site, a similar issue to CVE-2014-8638.

Weaknesses
CWE-352
Cross-Site Request Forgery (CSRF)
Related CVEs
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2015-04-01 10:59:08
(9 years ago)
Updated Date
2017-01-03 02:59:43
(7 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 36.0.4 and prior versions cpe:2.3:a:mozilla:firefox <= 36.0.4
  Mozilla Firefox Esr 31.0 cpe:2.3:a:mozilla:firefox_esr:31.0
  Mozilla Firefox Esr 31.1 cpe:2.3:a:mozilla:firefox_esr:31.1
  Mozilla Firefox Esr 31.1.0 cpe:2.3:a:mozilla:firefox_esr:31.1.0
  Mozilla Firefox Esr 31.1.1 cpe:2.3:a:mozilla:firefox_esr:31.1.1
  Mozilla Firefox Esr 31.2 cpe:2.3:a:mozilla:firefox_esr:31.2
  Mozilla Firefox Esr 31.3 cpe:2.3:a:mozilla:firefox_esr:31.3
  Mozilla Firefox Esr 31.3.0 cpe:2.3:a:mozilla:firefox_esr:31.3.0
  Mozilla Firefox Esr 31.4 cpe:2.3:a:mozilla:firefox_esr:31.4
  Mozilla Firefox Esr 31.5 cpe:2.3:a:mozilla:firefox_esr:31.5
  Mozilla Firefox Esr 31.5.1 cpe:2.3:a:mozilla:firefox_esr:31.5.1
  Mozilla Firefox Esr 31.5.2 cpe:2.3:a:mozilla:firefox_esr:31.5.2
  Mozilla Firefox Esr 31.5.3 cpe:2.3:a:mozilla:firefox_esr:31.5.3
  Mozilla Thunderbird 31.5 and prior versions cpe:2.3:a:mozilla:thunderbird <= 31.5
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...