PT-2020-6745 · Mozilla+4 · Firefox+4
Kevin Higgs
·
Published
2020-06-30
·
Updated
2024-12-12
·
CVE-2020-12415
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 78
Description
The issue is related to Firefox's AppCache behavior when a "%" character followed by "2F" is present in a manifest URL. This could cause the appcache to be used to service requests for the top level directory, potentially allowing a remote attacker to disclose protected information.
Recommendations
For versions prior to 78, update to version 78 or later to resolve the issue.
Exploit
Fix
Incorrect Default Permissions
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Firefox
Linuxmint
Suse
Ubuntu