2024-05-17 20:03:31 +00:00
{
"id" : "CVE-2024-5022" ,
"sourceIdentifier" : "security@mozilla.org" ,
"published" : "2024-05-17T19:15:07.537" ,
2025-04-04 16:04:00 +00:00
"lastModified" : "2025-04-04T14:25:28.007" ,
"vulnStatus" : "Analyzed" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2024-05-17 20:03:31 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "The file scheme of URLs would be hidden, resulting in potential spoofing of a website's address in the location bar This vulnerability affects Focus for iOS < 126."
2024-05-26 02:03:22 +00:00
} ,
{
"lang" : "es" ,
"value" : " El esquema de archivos de las URL estar\u00eda oculto, lo que dar\u00eda como resultado una posible falsificaci\u00f3n de la direcci\u00f3n de un sitio web en la barra de direcciones. Esta vulnerabilidad afecta a Focus para iOS < 126."
2024-05-17 20:03:31 +00:00
}
] ,
2024-10-29 08:00:49 +00:00
"metrics" : {
"cvssMetricV31" : [
{
"source" : "134c704f-9b21-4f2e-91b3-4a467353bcc0" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 4.4 ,
"baseSeverity" : "MEDIUM" ,
2024-10-29 08:00:49 +00:00
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2024-10-29 08:00:49 +00:00
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 2.5
}
]
} ,
2025-04-04 16:04:00 +00:00
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mozilla:firefox_focus:*:*:*:*:*:iphone_os:*:*" ,
"versionEndExcluding" : "126.0" ,
"matchCriteriaId" : "4A474B93-4C7B-4010-9326-B0CD19E0963E"
}
]
}
]
}
] ,
2024-05-17 20:03:31 +00:00
"references" : [
{
"url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=1874560" ,
2025-04-04 16:04:00 +00:00
"source" : "security@mozilla.org" ,
"tags" : [
"Issue Tracking"
]
2024-05-17 20:03:31 +00:00
} ,
{
"url" : "https://www.mozilla.org/security/advisories/mfsa2024-24/" ,
2025-04-04 16:04:00 +00:00
"source" : "security@mozilla.org" ,
"tags" : [
"Vendor Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=1874560" ,
2025-04-04 16:04:00 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Issue Tracking"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://www.mozilla.org/security/advisories/mfsa2024-24/" ,
2025-04-04 16:04:00 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
2024-05-17 20:03:31 +00:00
}
]
}