CVE-2017-7797: High severity firefox vulnerability
Published Aug 8, 2017
·Updated
Response header name interning does not have same-origin protections and these headers are stored in a global registry. This allows stored header names to be available cross-origin.
Affected Software
2 affected componentsFixes available
Mozilla Firefox<55
55
Mozilla Firefox<55.0
Remediation
Patch Available
Event History
Aug 8, 2017
CVE Published
12:00 AM
Jun 11, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-7798
- CVE-2017-7800
- CVE-2017-7801
- CVE-2017-7809
- CVE-2017-7784
- CVE-2017-7802
- CVE-2017-7785
- CVE-2017-7786
- CVE-2017-7806
- CVE-2017-7753
- CVE-2017-7787
- CVE-2017-7807
- CVE-2017-7792
- CVE-2017-7804
- CVE-2017-7791
- CVE-2017-7808
- CVE-2017-7782
- CVE-2017-7781
- CVE-2017-7794
- CVE-2017-7803
- CVE-2017-7799
- CVE-2017-7783
- CVE-2017-7788
- CVE-2017-7789
- CVE-2017-7790
- CVE-2017-7796
- CVE-2017-7797
- CVE-2017-7780
- CVE-2017-7779
Frequently Asked Questions
1
What is the severity of CVE-2017-7797?
CVE-2017-7797 has a high severity rating due to its potential for cross-origin exposure of header names.
2
How do I fix CVE-2017-7797?
To mitigate CVE-2017-7797, upgrade your Mozilla Firefox to version 55 or later.
3
Which versions of Firefox are affected by CVE-2017-7797?
CVE-2017-7797 affects all versions of Mozilla Firefox prior to version 55.
4
What type of vulnerability is CVE-2017-7797?
CVE-2017-7797 is a vulnerability related to inadequate same-origin protections for response header name interning.
5
What impact does CVE-2017-7797 have on users?
CVE-2017-7797 can allow attackers to access response headers across different origins, potentially leading to data exposure.