CVE-2022-26384 - log back

CVE-2022-26384 edited at 14 May 2022 20:59:39
Severity
- Unknown
+ High
Remote
- Unknown
+ Remote
Description
+ If an attacker could control the contents of an iframe sandboxed with allow-popups but not allow-scripts, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox.
References
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1744352
Notes
CVE-2022-26384 created at 14 May 2022 20:52:47