公告ID: KYLIN-2019-11712
安全等级: 重要
产品: Kylin V3
发布日期: 2019年7月10日
CVE: CVE-2019-11712
CVSS3评分: 7.5
概述:
None 描述:
POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. 系统版本:
KYLIN 3.0.x
KYLIN 3.2.x
KYLIN 3.2.x
KYLIN 3.3.x
KYLIN 3.3.x
KYLIN 3.4.x
KYLIN 3.4.x
受影响包列表:
firefox
firefox-60.8.0-1.el6_10
thunderbird-60.8.0-1.el6_10
firefox-60.8.0-1.el7_6
thunderbird-60.8.0-1.el7_6
firefox-60.8.0-1.el8_0
thunderbird-60.8.0-1.el8_0