The fetch API implementation in Mozilla Firefox before 41.0.2 does not restrict access to the HTTP response body in certain situations where user credentials are supplied but the CORS cross-origin request algorithm is improperly followed, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
CVSS Details
- CVSS 3.1 Base Score: 8.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-firefoxUpgrade firefox | Dec 10, 2025 | Oct 16, 2015 |
| Mfsa2015 115 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 41.0.2 | Oct 22, 2015 | Oct 18, 2015 |
| Oracle Solaris | — | Upgrade database/sqlite-3/documentation to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade web/browser/firefox to version 38.4.0-0.175.3.8.0.2.0 on Solaris 11.3Upgrade runtime/tcl-8/tcl-sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3 | May 29, 2017 | Oct 18, 2015 |
| Suse | — | Upgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-develUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-common | Dec 18, 2015 | Oct 18, 2015 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Oct 18, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub