PT-2020-19245 · Mozilla+2 · Firefox+2

Leon Visscher

·

Published

2020-04-07

·

Updated

2024-12-12

·

CVE-2020-6823

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 75
Description A malicious extension could exploit the issue by calling the browser.identity.launchWebAuthFlow function, controlling the redirect uri, and obtaining the Auth code through the returned Promise, potentially gaining access to the user's account at the service provider.
Recommendations For versions prior to 75, update to version 75 or later to resolve the issue. As a temporary workaround, consider restricting the use of the browser.identity.launchWebAuthFlow function until a patch is applied.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1760
ALT-PU-2020-2408
ALT-PU-2020-2933
ALT-PU-2020-3442
ALT-PU-2021-1368
ALT-PU-2021-3368
CVE-2020-6823
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
USN-4323-1

Affected Products

Alt Linux
Firefox
Ubuntu