CVE-2015-0807: CSRF
The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x status codes for redirects after a preflight request has occurred, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site, a similar issue to CVE-2014-8638.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0807?
CVE-2015-0807 has been assigned a medium severity rating due to the potential for remote attackers to bypass CORS access control checks.
How do I fix CVE-2015-0807?
To fix CVE-2015-0807, update Mozilla Firefox to version 37.0 or later, or to Firefox ESR version 31.6 or later.
Which versions of Mozilla Firefox are affected by CVE-2015-0807?
Versions of Mozilla Firefox below 37.0, Firefox ESR versions before 31.6, and Thunderbird versions before 31.6 are affected by CVE-2015-0807.
How does CVE-2015-0807 impact CORS security?
CVE-2015-0807 allows remote attackers to bypass intended CORS access-control checks through the misuse of HTTP 30x status codes.
What software applications are affected by CVE-2015-0807?
CVE-2015-0807 affects Mozilla Firefox, Firefox ESR, and Thunderbird applications running specified vulnerable versions.