FireFox KB is reporting version 113 and 114 in CPE as version 0.0.0 triggering vulnerabilities for FireFox <1.x
Categories
(Firefox :: Untriaged, defect)
Tracking
()
People
(Reporter: max_ali07, Unassigned)
Details
Steps to reproduce:
Scan windows hosts with Tenable Security Center for Mozilla Firefox related plugins.
Application CPE output:
cpe:/a:mozilla:firefox:0.0.0 -> Mozilla Firefox
cpe:/a:mozilla:mozilla:'114.0' -> Mozilla Mozilla
Actual results:
Scan results come back with:
Plugin IDs:
14181 Firefox < 1.0 Multiple Spoofing Vulnerabilities
12642 Mozilla Browsers shell: URI Arbitrary Command Execution
14668 Mozilla Multiple Browsers CA Certificate SSL Page DoS
14728 Mozilla Browsers Multiple Vulnerabilities
15432 Mozilla Multiple Products XPInstall Arbitrary File Overwrite
23930 Firefox < 1.5.0.9 / 2.0.0.1 Multiple Vulnerabilities
24701 Firefox < 1.5.0.10 / 2.0.0.2 Multiple Vulnerabilities
24875 Firefox < 1.5.0.11 / 2.0.0.3 Multiple Vulnerabilities
25349 Firefox < 1.5.0.12 / 2.0.0.4 Multiple Vulnerabilities
175408 Microsoft Teams < 1.6.0.11166 Information Disclosure
See Tenable Plugin documentation for plugin details.
No FilePath is provided with any of the above-reported vulnerabilities.
Expected results:
Mozilla KB version reporting should:
cpe:/a:mozilla:firefox:114.0 -> Mozilla Firefox
cpe:/a:mozilla:mozilla:'114.0' -> Mozilla Mozilla
Comment 1•3 years ago
|
||
Similar report on SUMO (unsolved): https://support.mozilla.org/questions/1415186
Comment 2•3 years ago
|
||
The Bugbug bot thinks this bug should belong to the 'Core::Security: PSM' component, and is moving the bug to that component. Please correct in case you think the bot is wrong.
Comment 3•3 years ago
|
||
Sounds like a bug in Tenable Security Center?
Bug resolved by plug-in updates from the Tenable to read the cpr correctly
Comment 5•3 years ago
|
||
Great - thanks!
Description
•