Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-15677

Опубликовано: 01 окт. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5.8
CVSS3: 6.1

Описание

By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.

РелизСтатусПримечание
bionic

released

81.0+build2-0ubuntu0.18.04.1
devel

released

81.0+build2-0ubuntu1
esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

released

81.0+build2-0ubuntu0.20.04.1
groovy

released

81.0+build2-0ubuntu1
hirsute

released

81.0+build2-0ubuntu1
impish

released

81.0+build2-0ubuntu1
jammy

released

81.0+build2-0ubuntu1
kinetic

released

81.0+build2-0ubuntu1

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

DNE

esm-apps/bionic

ignored

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

impish

DNE

jammy

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

DNE

esm-apps/focal

ignored

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

focal

ignored

groovy

ignored

end of life
hirsute

DNE

impish

DNE

jammy

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

impish

DNE

jammy

DNE

kinetic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

focal

ignored

groovy

ignored

end of life
hirsute

DNE

impish

DNE

jammy

DNE

kinetic

DNE

Показывать по

РелизСтатусПримечание
bionic

released

1:78.8.1+build1-0ubuntu0.18.04.1
devel

not-affected

1:78.4.3+build1-0ubuntu1
esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

released

1:78.7.1+build1-0ubuntu0.20.04.1
groovy

not-affected

1:78.3.2+build1-0ubuntu1
hirsute

not-affected

1:78.4.3+build1-0ubuntu1
impish

not-affected

1:78.4.3+build1-0ubuntu1
jammy

not-affected

1:78.4.3+build1-0ubuntu1
kinetic

not-affected

1:78.4.3+build1-0ubuntu1

Показывать по

EPSS

Процентиль: 66%
0.00527
Низкий

5.8 Medium

CVSS2

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
redhat
почти 5 лет назад

By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.

CVSS3: 6.1
nvd
почти 5 лет назад

By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.

CVSS3: 6.1
debian
почти 5 лет назад

By exploiting an Open Redirect vulnerability on a website, an attacker ...

CVSS3: 6.1
github
больше 3 лет назад

By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.

suse-cvrf
почти 5 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 66%
0.00527
Низкий

5.8 Medium

CVSS2

6.1 Medium

CVSS3