A same-origin policy violation could have allowed the...
High severity
Unreviewed
Published
Dec 22, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Dec 22, 2022
Published to the GitHub Advisory Database
Dec 22, 2022
Last updated
Jan 27, 2023
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via
performance.getEntries()
. This vulnerability affects Thunderbird < 102.4, Firefox ESR < 102.4, and Firefox < 106.References