CVE-2025-0239
⚪ Do wiadomości
Błąd walidacji certyfikatów w Alt-Svc w Firefox umożliwia przekierowanie na niezabezpieczoną stronę.
CVSS
4.0
EPSS
0.2%
Exploit
none
Vendor
mozilla
Opis źródłowy (NVD)
When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 4.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2025-01-07 16:15:38 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 19:10:01 UTC |
Referencje
- https://bugzilla.mozilla.org/show_bug.cgi?id=1929156 ([email protected]) [Issue Tracking, Permissions Required]
- https://www.mozilla.org/security/advisories/mfsa2025-01/ ([email protected]) [Vendor Advisory]
- https://www.mozilla.org/security/advisories/mfsa2025-02/ ([email protected]) [Vendor Advisory]
- https://www.mozilla.org/security/advisories/mfsa2025-04/ ([email protected]) [Vendor Advisory]
- https://www.mozilla.org/security/advisories/mfsa2025-05/ ([email protected]) [Vendor Advisory]
- https://lists.debian.org/debian-lts-announce/2025/01/msg00004.html (af854a3a-2127-422b-91ae-364da2661108)