PT-2021-23860 · Mozilla+2 · Firefox+2

Ademar Nowasky Junior

·

Published

2021-11-02

·

Updated

2023-09-22

·

CVE-2021-43532

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 94
Description The issue allows a website to potentially steal authentication tokens by tricking a user into copying and pasting an image link that contains the token. This can happen when an image triggers authentication flows and a Content Security Policy stops a redirection chain, resulting in the final image URL containing the authentication token. The estimated number of potentially affected devices is not specified.
Recommendations For Firefox versions prior to 94, update to version 94 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the 'Copy Image Link' context menu action until the update is applied. Restrict access to sensitive information when copying and pasting links from untrusted websites to minimize the risk of exploitation.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3215
ALT-PU-2021-3391
ALT-PU-2022-2458
ALT-PU-2022-2929
ALT-PU-2023-1138
ALT-PU-2023-1139
ALT-PU-2023-4336
ALT-PU-2023-4339
CVE-2021-43532
OESA-2023-1673
OESA-2023-1674

Affected Products

Alt Linux
Astra Linux
Firefox