CVE-2017-7791 - log back

CVE-2017-7791 created at 25 Sep 2019 19:31:40
Severity
+ Medium
Remote
+ Remote
Type
+ Content spoofing
Description
+ A content spoofing issue has been found in firefox < 55.0 and thunderbird < 52.3. On pages containing an iframe, the data: protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert from the iframe content.
References
+ https://www.mozilla.org/en-US/security/advisories/mfsa2017-18/#CVE-2017-7791
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1365875
Notes