Loading HuntDB...

GHSA-x2m9-q3vv-hr85

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

By navigating a tab using the history API, an attacker could cause the address bar to display the incorrect domain (with the https:// scheme, a blocked port number such as '1', and without a lock icon) while controlling the page contents. This vulnerability affects Firefox < 70.

Related CVEs

Key Information

GHSA ID
GHSA-x2m9-q3vv-hr85
Published
May 24, 2022 5:22 PM
Last Modified
May 24, 2022 5:22 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 13, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.