Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-26962

Опубликовано: 09 дек. 2020
Источник: debian
EPSS Низкий

Описание

Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This vulnerability affects Firefox < 83.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed83.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2020-50/#CVE-2020-26962

EPSS

Процентиль: 44%
0.00219
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 5 лет назад

Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This vulnerability affects Firefox < 83.

CVSS3: 6.1
nvd
около 5 лет назад

Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This vulnerability affects Firefox < 83.

github
больше 3 лет назад

Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This vulnerability affects Firefox < 83.

EPSS

Процентиль: 44%
0.00219
Низкий