Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-26976

Опубликовано: 07 янв. 2021
Источник: debian
EPSS Низкий

Описание

When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed84.0-1package
firefox-esrfixed78.7.0esr-1package
thunderbirdfixed1:78.7.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2021-04/#CVE-2020-26976

  • https://www.mozilla.org/en-US/security/advisories/mfsa2020-54/#CVE-2020-26976

  • https://www.mozilla.org/en-US/security/advisories/mfsa2021-05/#CVE-2020-26976

EPSS

Процентиль: 83%
0.01973
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 5 лет назад

When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.

CVSS3: 6.1
redhat
около 5 лет назад

When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.

CVSS3: 6.5
nvd
около 5 лет назад

When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.

github
больше 3 лет назад

When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.

suse-cvrf
около 5 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 83%
0.01973
Низкий