PT-2021-15640 · Mozilla+4 · Firefox+4
Tjr
+1
·
Published
2021-03-23
·
Updated
2024-12-12
·
CVE-2021-23985
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Firefox versions prior to 87
Description:
The issue allows an attacker to enable the Devtools remote debugging feature unnoticed by the user, potentially by altering specific about:config values, such as those modified by malware running on the user's computer. This could enable a remote attacker, who can make a direct network connection to the victim, to monitor the user's browsing activity and plaintext network traffic. A visual cue has been introduced for Devtools when it has an open network socket to address this issue.
Recommendations:
For Firefox versions prior to 87, update to version 87 or later to resolve the issue. As a temporary workaround, consider disabling the Devtools remote debugging feature until the update can be applied. Restrict access to the about:config values to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Firefox
Linuxmint
Ubuntu