First published: Thu May 14 2015(Updated: )
Mozilla Firefox before 38.0 does not recognize a referrer policy delivered by a referrer META element in cases of context-menu navigation and middle-click navigation, which allows remote attackers to obtain sensitive information by reading web-server Referer logs that contain private data in a URL, as demonstrated by a private path component.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE | =13.1 | |
openSUSE | =13.2 | |
Mozilla Firefox | <=37.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2711 has been classified as a moderate severity vulnerability.
To fix CVE-2015-2711, update Mozilla Firefox to version 38.0 or later.
CVE-2015-2711 affects Mozilla Firefox versions up to and including 37.0.2, as well as specific versions of OpenSUSE.
CVE-2015-2711 allows attackers to access sensitive information through web-server Referer logs due to improper handling of referrer policies.
Yes, CVE-2015-2711 can potentially lead to data leaks by exposing private data in URLs.