Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-15676

Опубликовано: 22 сент. 2020
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.

The Mozilla Foundation Security Advisory describes this flaw as: Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5firefoxOut of support scope
Red Hat Enterprise Linux 5thunderbirdOut of support scope
Red Hat Enterprise Linux 6firefoxFixedRHSA-2020:383524.09.2020
Red Hat Enterprise Linux 6thunderbirdFixedRHSA-2020:415801.10.2020
Red Hat Enterprise Linux 7firefoxFixedRHSA-2020:408030.09.2020
Red Hat Enterprise Linux 7thunderbirdFixedRHSA-2020:416301.10.2020
Red Hat Enterprise Linux 8firefoxFixedRHSA-2020:383224.09.2020
Red Hat Enterprise Linux 8thunderbirdFixedRHSA-2020:415501.10.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsfirefoxFixedRHSA-2020:383424.09.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsthunderbirdFixedRHSA-2020:415601.10.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1881665Mozilla: XSS when pasting attacker-controlled data into a contenteditable element

EPSS

Процентиль: 79%
0.01265
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 5 лет назад

Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.

CVSS3: 6.1
nvd
почти 5 лет назад

Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.

CVSS3: 6.1
debian
почти 5 лет назад

Firefox sometimes ran the onload handler for SVG elements that the DOM ...

CVSS3: 6.1
github
больше 3 лет назад

Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.

suse-cvrf
почти 5 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 79%
0.01265
Низкий

6.1 Medium

CVSS3