PT-2020-14570 · Mozilla+3 · Firefox+4

Frederik Braun

·

Published

2020-07-08

·

Updated

2021-11-26

·

CVE-2020-15648

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Thunderbird versions prior to 78 Firefox versions prior to 78.0.2
Description The issue allows framing of other websites using object or embed tags, despite those websites disallowing framing with the X-Frame-Options header.
Recommendations For Thunderbird versions prior to 78, update to version 78 or later. For Firefox versions prior to 78.0.2, update to version 78.0.2 or later.

Fix

Clickjacking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2354
ALT-PU-2020-2408
ALT-PU-2020-2709
ALT-PU-2020-2933
ALT-PU-2020-2934
ALT-PU-2020-3442
ALT-PU-2021-1368
ALT-PU-2021-1369
ALT-PU-2021-3368
CESA-2020_3557
CVE-2020-15648
MGASA-2020-0378
RHSA-2020:3555
RHSA-2020:3557
RHSA-2020:3559
RHSA-2020:4080
RHSA-2020_3557
RHSA-2020_4080

Affected Products

Alt Linux
Centos
Firefox
Red Hat
Thunderbird