PT-2019-19973 · Mozilla+1 · Firefox+1

Adrian Karolak

·

Published

2019-10-22

·

Updated

2021-02-18

·

CVE-2020-12412

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 70
Description The issue allows an attacker to manipulate the address bar, displaying an incorrect domain with the https:// scheme, a blocked port number, and without a lock icon, while controlling the page contents. This is achieved by navigating a tab using the history API.
Recommendations For versions prior to 70, update to version 70 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2019-3087
ALT-PU-2020-1617
ALT-PU-2020-2408
ALT-PU-2020-2933
ALT-PU-2021-1368
CVE-2020-12412

Affected Products

Alt Linux
Firefox