PT-2020-16588 · Mozilla+7 · Firefox+7

Andrew Sutherland

·

Published

2020-12-15

·

Updated

2024-12-12

·

CVE-2020-26976

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 84
Description The issue occurs when a HTTPS page is embedded in a HTTP page and a service worker is registered for the secure page. In such cases, the service worker could intercept the request for the secure page, despite the iframe not being a secure context due to the insecure framing.
Recommendations For versions prior to 84, update to version 84 or later to resolve the issue. As a temporary workaround, consider disabling service workers for secure pages embedded in insecure contexts until a patch is available. Restrict access to sensitive information on secure pages to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2020-3529
ALT-PU-2021-1158
ALT-PU-2021-1160
ALT-PU-2021-1199
ALT-PU-2021-1200
ALT-PU-2021-1368
ALT-PU-2021-1369
ALT-PU-2021-2725
ALT-PU-2021-2881
ALT-PU-2021-3368
ALT-PU-2021-3369
ALT-PU-2022-1781
ALT-PU-2022-1782
CESA-2021_0288
CESA-2021_0298
CVE-2020-26976
DLA-2539-1
DLA-2541-1
DSA-4840-1
DSA-4842-1
MGASA-2021-0065
MGASA-2021-0066
OESA-2023-1673
OESA-2023-1674
OPENSUSE-SU-2021:0208-1
OPENSUSE-SU-2021:0209-1
OPENSUSE-SU-2021:0222-1
OPENSUSE-SU-2021:0223-1
OPENSUSE-SU-2021_0208-1
OPENSUSE-SU-2021_0209-1
OPENSUSE-SU-2021_0222-1
OPENSUSE-SU-2021_0223-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:10601-1
OPENSUSE-SU-2024:14572-1
RHSA-2021:0285
RHSA-2021:0288
RHSA-2021:0289
RHSA-2021:0290
RHSA-2021:0297
RHSA-2021:0298
RHSA-2021:0299
RHSA-2021:0397
RHSA-2021_0288
RHSA-2021_0290
RHSA-2021_0297
RHSA-2021_0298
SUSE-SU-2021:0241-1
SUSE-SU-2021:0245-1
SUSE-SU-2021:0246-1
SUSE-SU-2021:0257-1
SUSE-SU-2021:0259-1
SUSE-SU-2021:14609-1
SUSE-SU-2021_0241-1
SUSE-SU-2021_0246-1
SUSE-SU-2021_0259-1
SUSE-SU-2021_14609-1
USN-4671-1
USN-4736-1

Affected Products

Alt Linux
Astra Linux
Centos
Firefox
Linuxmint
Red Hat
Suse
Ubuntu