PT-2020-5614 · Mozilla+6 · Firefox+8

Ophir Lojkine

·

Published

2020-05-05

·

Updated

2024-12-12

·

CVE-2020-12392

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Firefox ESR versions 68.7 and earlier Firefox versions prior to 76 Thunderbird versions prior to 68.8.0
Description The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in the disclosure of local files.
Recommendations For Firefox ESR versions 68.7 and earlier, update to version 68.8 or later. For Firefox versions prior to 76, update to version 76 or later. For Thunderbird versions prior to 68.8.0, update to version 68.8.0 or later. As a temporary workaround, consider avoiding the use of the 'Copy as cURL' feature until a patch is available.

Exploit

Fix

Information Disclosure

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1915
ALT-PU-2020-1916
ALT-PU-2020-1932
ALT-PU-2020-1933
ALT-PU-2020-1943
ALT-PU-2020-2408
ALT-PU-2020-2933
ALT-PU-2020-3442
ALT-PU-2021-1368
ALT-PU-2021-3368
BDU:2021-01269
CESA-2020_2031
CESA-2020_2036
CESA-2020_2037
CESA-2020_2046
CESA-2020_2049
CESA-2020_2050
CVE-2020-12392
DLA-2205-1
DLA-2206-1
DSA-4678-1
DSA-4683-1
MGASA-2020-0208
MGASA-2020-0209
OPENSUSE-SU-2020:0621-1
OPENSUSE-SU-2020:0643-1
OPENSUSE-SU-2020_0621-1
OPENSUSE-SU-2020_0643-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:10601-1
OPENSUSE-SU-2024:14572-1
RHSA-2020:2031
RHSA-2020:2032
RHSA-2020:2033
RHSA-2020:2036
RHSA-2020:2037
RHSA-2020:2046
RHSA-2020:2047
RHSA-2020:2048
RHSA-2020:2049
RHSA-2020:2050
RHSA-2020_2031
RHSA-2020_2036
RHSA-2020_2037
RHSA-2020_2046
RHSA-2020_2049
RHSA-2020_2050
SUSE-SU-2020:1209-1
SUSE-SU-2020:1218-1
SUSE-SU-2020:1225-1
SUSE-SU-2020:14359-1
USN-4353-1
USN-4353-2
USN-4373-1

Affected Products

Alt Linux
Centos
Firefox
Firefox Esr
Linuxmint
Red Hat
Suse
Thunderbird
Ubuntu