CVE-2015-4478: Infoleak
Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 do not impose certain ECMAScript 6 requirements on JavaScript object properties, which allows remote attackers to bypass the Same Origin Policy via the reviver parameter to the JSON.parse method.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4478?
CVE-2015-4478 has a medium severity level due to its potential to bypass the Same Origin Policy.
How do I fix CVE-2015-4478?
To fix CVE-2015-4478, upgrade to Mozilla Firefox version 40.0 or later, or Firefox ESR 38.2 or later.
What software is affected by CVE-2015-4478?
CVE-2015-4478 affects specific versions of Mozilla Firefox, Firefox ESR, Ubuntu 12.04, 14.04, 15.04, and openSUSE 13.1 and 13.2.
What type of vulnerability is CVE-2015-4478?
CVE-2015-4478 is a Cross-Origin Resource Sharing (CORS) vulnerability that allows unauthorized access to resources.
How can attackers exploit CVE-2015-4478?
Attackers can exploit CVE-2015-4478 by using the reviver parameter in the JSON.parse method to bypass security restrictions.