CVE Vulnerabilities

CVE-2015-7193

Published: Nov 05, 2015 | Modified: Oct 22, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
5.1 IMPORTANT
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly follow the CORS cross-origin request algorithm for the POST method in situations involving an unspecified Content-Type header manipulation, which allows remote attackers to bypass the Same Origin Policy by leveraging the lack of a preflight-request step.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla 38.0 (including) 38.0 (including)
Firefox Mozilla 38.0.1 (including) 38.0.1 (including)
Firefox Mozilla 38.0.5 (including) 38.0.5 (including)
Firefox Mozilla 38.1.0 (including) 38.1.0 (including)
Firefox Mozilla 38.1.1 (including) 38.1.1 (including)
Firefox Mozilla 38.2.0 (including) 38.2.0 (including)
Firefox Mozilla 38.2.1 (including) 38.2.1 (including)
Firefox Mozilla 38.3.0 (including) 38.3.0 (including)
Red Hat Enterprise Linux 5 RedHat firefox-0:38.4.0-1.el5_11 *
Red Hat Enterprise Linux 5 RedHat thunderbird-0:38.4.0-1.el5_11 *
Red Hat Enterprise Linux 6 RedHat firefox-0:38.4.0-1.el6_7 *
Red Hat Enterprise Linux 6 RedHat thunderbird-0:38.4.0-1.el6_7 *
Red Hat Enterprise Linux 7 RedHat firefox-0:38.4.0-1.el7_1 *
Red Hat Enterprise Linux 7 RedHat thunderbird-0:38.4.0-1.el7_2 *
Firefox Ubuntu devel *
Firefox Ubuntu precise *
Firefox Ubuntu trusty *
Firefox Ubuntu upstream *
Firefox Ubuntu vivid *
Firefox Ubuntu wily *
Thunderbird Ubuntu devel *
Thunderbird Ubuntu precise *
Thunderbird Ubuntu trusty *
Thunderbird Ubuntu upstream *
Thunderbird Ubuntu vivid *
Thunderbird Ubuntu wily *

References