Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Public Key Pinning (PKP) implementation in Mozilla Firefox before 33.0 does not properly consider the connection-coalescing behavior of SPDY and HTTP/2 in the case of a shared IP address, which allows man-in-the-middle attackers to bypass an intended pinning configuration and spoof a web site by providing a valid certificate from an arbitrary recognized Certification Authority.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox 安全绕过漏洞
Vulnerability Description
Mozilla Firefox是美国Mozilla基金会开发的一款开源Web浏览器。 Mozilla Firefox 33.0之前版本的Public Key Pinning (PKP)实现中存在安全漏洞,该漏洞源于程序没有正确处理共享IP地址上的SPDY和HTTP/2的connection-coalescing。攻击者可通过提供任意Certification Authority的有效证书利用该漏洞绕过既定的pinning配置,伪造Web站点,实施中间人攻击。
CVSS Information
N/A
Vulnerability Type
N/A