Security Advisory

CVE-2015-4520

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-09-24 01:00:00
Last updated 2024-08-06 06:18:11
Assigner mozilla
CVSS score not scored
State PUBLISHED

Description

Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to bypass CORS preflight protection mechanisms by leveraging (1) duplicate cache-key generation or (2) retrieval of a value from an incorrect HTTP Access-Control-* response header.