Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Andrey

#42296de 56,330
6.8CVSS total
Vulnerabilidades · 1
PT-2018-3985
6.8
2018-08-15
Mozilla · Firefox · CVE-2019-11725
**Name of the Vulnerable Software and Affected Versions** Firefox versions prior to 68 **Description** The issue is related to shortcomings in the authorization procedure of the Firefox web browser. It may allow a remote attacker to compromise data integrity. When a user visits a site marked as unsafe by the Safebrowsing API, warning messages are displayed, but resources from the same site loaded through websockets are not blocked, leading to the loading of unsafe resources and bypassing safebrowsing protections. **Recommendations** For Firefox versions prior to 68, update to version 68 or later to resolve the issue. As a temporary workaround, consider restricting the use of websockets for sites marked as unsafe by the Safebrowsing API until a patch is available. Avoid using websockets to load resources from potentially unsafe sites until the issue is resolved.