CVE-2014-8638

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.
References
Link Resource
http://www.mozilla.org/security/announce/2014/mfsa2015-03.html Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1080987
http://secunia.com/advisories/62242
http://secunia.com/advisories/62250
http://www.securitytracker.com/id/1031533
http://secunia.com/advisories/62237
http://secunia.com/advisories/62446
http://secunia.com/advisories/62790
http://secunia.com/advisories/62657
http://www.debian.org/security/2015/dsa-3127
http://lists.opensuse.org/opensuse-updates/2015-01/msg00071.html
http://rhn.redhat.com/errata/RHSA-2015-0046.html
http://www.debian.org/security/2015/dsa-3132
http://www.ubuntu.com/usn/USN-2460-1
http://rhn.redhat.com/errata/RHSA-2015-0047.html
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00014.html
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00032.html
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00033.html
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00036.html
http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
https://security.gentoo.org/glsa/201504-01
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html
http://www.securitytracker.com/id/1031534
http://www.securityfocus.com/bid/72047
http://secunia.com/advisories/62418
http://secunia.com/advisories/62316
http://secunia.com/advisories/62315
http://secunia.com/advisories/62313
http://secunia.com/advisories/62304
http://secunia.com/advisories/62293
http://secunia.com/advisories/62283
http://secunia.com/advisories/62274
http://secunia.com/advisories/62273
http://secunia.com/advisories/62259
http://secunia.com/advisories/62253
http://linux.oracle.com/errata/ELSA-2015-0047.html
http://linux.oracle.com/errata/ELSA-2015-0046.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/99958
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox_esr:31.3.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.1.1:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*

Information

Published : 2015-01-14 03:59

Updated : 2017-09-07 18:29


NVD link : CVE-2014-8638

Mitre link : CVE-2014-8638


JSON object : View

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

Advertisement

dedicated server usa

Products Affected

mozilla

  • firefox
  • firefox_esr
  • seamonkey
  • thunderbird