PT-2020-16570 · Mozilla+1 · Firefox For Android+1

Muneaki Nishimura

·

Published

2020-11-21

·

Updated

2024-12-12

·

CVE-2020-26955

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Firefox for Android versions prior to 83
Description The issue occurs when a user downloads a file in Firefox for Android and a cookie is set. In such cases, the cookie would be re-sent during subsequent file download operations on the same domain, regardless of whether the original and subsequent requests were made in private or non-private browsing modes. This issue is specific to Firefox for Android, with other operating systems being unaffected.
Recommendations For Firefox for Android versions prior to 83, update to version 83 or later to resolve the issue. As a temporary workaround, consider restricting the use of cookies for file download operations or clearing cookies after each download to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3384
ALT-PU-2021-3368
CVE-2020-26955
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1

Affected Products

Alt Linux
Firefox For Android