PT-2020-16576 · Mozilla+3 · Firefox+3
Paul Stone
·
Published
2020-11-17
·
Updated
2024-12-12
·
CVE-2020-26962
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 83
Description
The issue allows cross-origin iframes with a login form to be recognized and populated by the login autofill service. This could be exploited in clickjacking attacks and also allows data to be read across partitions in dynamic first party isolation.
Recommendations
For versions prior to 83, update to version 83 or later to resolve the issue. As a temporary workaround, consider disabling the login autofill service for cross-origin iframes until a patch is available. Restrict access to sensitive information in login forms to minimize the risk of exploitation.
Exploit
Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Firefox
Linuxmint
Ubuntu