When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is interrupted but resources from the same site loaded through websockets are not blocked, leading to the loading of unsafe resources and bypassing safebrowsing protections. This vulnerability affects Firefox < 68.
Link | Tags |
---|---|
https://www.mozilla.org/security/advisories/mfsa2019-21/ | vendor advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=1483510 | vendor advisory issue tracking permissions required |
https://security.gentoo.org/glsa/201908-12 | third party advisory vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00010.html | vendor advisory mailing list third party advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00009.html | vendor advisory mailing list third party advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00011.html | vendor advisory mailing list third party advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00017.html | vendor advisory mailing list third party advisory |