Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 do not enforce key pinning upon encountering an X.509 certificate problem that generates a user dialog, which allows user-assisted man-in-the-middle attackers to bypass intended access restrictions by triggering a (1) expired certificate or (2) mismatched hostname for a domain with pinning enabled.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2015-07-05 19:01
Updated : 2016-12-27 18:59
NVD link : CVE-2015-2741
Mitre link : CVE-2015-2741
JSON object : View
CWE
CWE-310
Cryptographic Issues
Products Affected
mozilla
- firefox
- firefox_esr
oracle
- solaris