PT-2020-16570 · Mozilla+1 · Firefox For Android+1
Muneaki Nishimura
·
Published
2020-11-21
·
Updated
2024-12-12
·
CVE-2020-26955
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox for Android versions prior to 83
Description
The issue occurs when a user downloads a file in Firefox for Android and a cookie is set. In such cases, the cookie would be re-sent during subsequent file download operations on the same domain, regardless of whether the original and subsequent requests were made in private or non-private browsing modes. This issue is specific to Firefox for Android, with other operating systems being unaffected.
Recommendations
For Firefox for Android versions prior to 83, update to version 83 or later to resolve the issue. As a temporary workaround, consider restricting the use of cookies for file download operations or clearing cookies after each download to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Firefox For Android