PT-2021-2601 · Mozilla+4 · Firefox+4
Jan-Ivar Bruaroey
·
Published
2021-01-26
·
Updated
2024-12-12
·
CVE-2021-23958
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 85
Description
The issue is related to errors in resource management, potentially allowing a remote attacker to gain unauthorized access to protected information. It could also cause the browser to leak unintended information by transferring a screen sharing state into another tab.
Recommendations
For versions prior to 85, update to version 85 or later to resolve the issue. As a temporary workaround, consider restricting screen sharing functionality until the update is applied.
Exploit
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Firefox
Linuxmint
Ubuntu