PT-2021-2597 · Mozilla+4 · Firefox+4
Paul Zühlcke
·
Published
2021-01-26
·
Updated
2024-12-12
·
CVE-2021-23963
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 85
Description
The issue is related to errors in handling permissions for the WebRTC extension in Mozilla Firefox. It may allow a remote attacker to impact data integrity. When sharing geolocation during an active WebRTC share, Firefox could reset the webRTC sharing state in the user interface, leading to loss of control over the currently granted permission.
Recommendations
For versions prior to 85, update to version 85 or later to resolve the issue. As a temporary workaround, consider avoiding the use of geolocation sharing during active WebRTC shares until the update is applied. Restrict access to WebRTC functionality to minimize the risk of exploitation.
Exploit
Fix
Improper Preservation of Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Firefox
Ubuntu