First published: Tue Mar 07 2017(Updated: )
An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and further spoofing attacks. This vulnerability affects Firefox < 52.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <52 | 52 |
Firefox | <52.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-5415 is classified as a moderate severity vulnerability.
The recommended fix for CVE-2017-5415 is to upgrade to Firefox version 52 or later.
CVE-2017-5415 affects all versions of Firefox prior to version 52.
CVE-2017-5415 can lead to user confusion and further spoofing attacks through URL spoofing.
There are no known workarounds for CVE-2017-5415 other than upgrading the browser.