CVE-2017-7820

Source
https://cve.org/CVERecord?id=CVE-2017-7820
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7820.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-7820
Downstream
Related
Published
2018-06-11T21:29:10.873Z
Modified
2026-03-14T09:24:01.483986Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

The "instanceof" operator can bypass the Xray wrapper mechanism. When called on web content from the browser itself or an extension the web content can provide its own result for that operator, possibly tricking the browser or extension into mishandling the element. This vulnerability affects Firefox < 56.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7820.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "55.0.3"
            }
        ]
    }
]