Closed Bug 1837069 Opened 3 years ago Closed 3 years ago

FireFox KB is reporting version 113 and 114 in CPE as version 0.0.0 triggering vulnerabilities for FireFox <1.x

Categories

(Firefox :: Untriaged, defect)

Firefox 114
defect

Tracking

()

RESOLVED INVALID

People

(Reporter: max_ali07, Unassigned)

Details

Steps to reproduce:

Scan windows hosts with Tenable Security Center for Mozilla Firefox related plugins.
Application CPE output:
cpe:/a:mozilla:firefox:0.0.0 -> Mozilla Firefox

cpe:/a:mozilla:mozilla:'114.0' -> Mozilla Mozilla

Actual results:

Scan results come back with:
Plugin IDs:
14181 Firefox < 1.0 Multiple Spoofing Vulnerabilities
12642 Mozilla Browsers shell: URI Arbitrary Command Execution
14668 Mozilla Multiple Browsers CA Certificate SSL Page DoS
14728 Mozilla Browsers Multiple Vulnerabilities
15432 Mozilla Multiple Products XPInstall Arbitrary File Overwrite
23930 Firefox < 1.5.0.9 / 2.0.0.1 Multiple Vulnerabilities
24701 Firefox < 1.5.0.10 / 2.0.0.2 Multiple Vulnerabilities
24875 Firefox < 1.5.0.11 / 2.0.0.3 Multiple Vulnerabilities
25349 Firefox < 1.5.0.12 / 2.0.0.4 Multiple Vulnerabilities
175408 Microsoft Teams < 1.6.0.11166 Information Disclosure
See Tenable Plugin documentation for plugin details.
No FilePath is provided with any of the above-reported vulnerabilities.

Expected results:

Mozilla KB version reporting should:
cpe:/a:mozilla:firefox:114.0 -> Mozilla Firefox

cpe:/a:mozilla:mozilla:'114.0' -> Mozilla Mozilla

Similar report on SUMO (unsolved): https://support.mozilla.org/questions/1415186

The Bugbug bot thinks this bug should belong to the 'Core::Security: PSM' component, and is moving the bug to that component. Please correct in case you think the bot is wrong.

Component: Untriaged → Security: PSM
Product: Firefox → Core

Sounds like a bug in Tenable Security Center?

Component: Security: PSM → Untriaged
Product: Core → Firefox

Bug resolved by plug-in updates from the Tenable to read the cpr correctly

Great - thanks!

Status: UNCONFIRMED → RESOLVED
Closed: 3 years ago
Resolution: --- → INVALID
You need to log in before you can comment on or make changes to this bug.