Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-6827

Опубликовано: 08 апр. 2020
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI.
Note: This issue only affects Firefox for Android. Other operating systems are unaffected.. This vulnerability affects Firefox ESR < 68.7.

The Mozilla Foundation Security Advisory describes this flaw as: When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI.

Отчет

This issue only affects Firefox for Android. Other operating systems are unaffected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5firefoxNot affected
Red Hat Enterprise Linux 6firefoxNot affected
Red Hat Enterprise Linux 7firefoxNot affected
Red Hat Enterprise Linux 8firefoxNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20->CWE-451
https://bugzilla.redhat.com/show_bug.cgi?id=1821968Mozilla: Custom Tabs in Firefox for Android could have the URI spoofed

EPSS

Процентиль: 55%
0.00321
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
nvd
больше 5 лет назад

When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. <br> *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7.

CVSS3: 4.7
debian
больше 5 лет назад

When following a link that opened an intent://-schemed URL, causing a ...

github
больше 3 лет назад

When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. <br> *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7.

suse-cvrf
больше 5 лет назад

Security update for MozillaFirefox

suse-cvrf
больше 5 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 55%
0.00321
Низкий

4.7 Medium

CVSS3