CVE-2015-7184

CVSS v2.0 6.8 (Medium)
68% Progress
EPSS 1.09 % (85th)
1.09% Progress
Affected Products 1
Advisories 2

The fetch API implementation in Mozilla Firefox before 41.0.2 does not restrict access to the HTTP response body in certain situations where user credentials are supplied but the CORS cross-origin request algorithm is improperly followed, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

Weaknesses
CWE-284
Improper Access Control
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2015-10-18 10:59:03
(9 years ago)
Updated Date
2016-12-24 02:59:36
(7 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 41.0.1 and prior versions cpe:2.3:a:mozilla:firefox <= 41.0.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...