Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Idira Identity Browser Extension: Unauthorized Application Interaction via Origin Validation Failure
Vulnerability Description
Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger unauthorized application interaction or execution parameters within the context of that authenticated browser session. CyberArk Security Bulletin: CA26-21
CVSS Information
N/A
Vulnerability Type
源验证错误
Vulnerability Title
CyberArk Idira Identity Browser Extension 访问控制错误漏洞
Vulnerability Description
CyberArk Idira Identity Browser Extension是美国CyberArk公司的一个浏览器身份认证扩展。 CyberArk Idira Identity Browser Extension 26.8.1之前版本存在访问控制错误漏洞,该漏洞源于内部网页验证例程中存在来源验证缺陷,可能导致经过身份验证的用户导航到特制网页时,远程攻击者触发未经授权的应用程序交互或执行参数。
CVSS Information
N/A
Vulnerability Type
N/A