PT-2021-2991 · Mozilla+4 · Firefox+4
Andrew Mccreight
·
Published
2021-04-19
·
Updated
2026-01-06
·
CVE-2021-24001
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 88
Description
The issue is related to errors in restricting security on testing infrastructure, which could allow a remote attacker to gain unauthorized access to protected information. A compromised content process could perform session history manipulations that it should not have been able to due to the testing infrastructure not being restricted to testing-only configurations.
Recommendations
For versions prior to 88, update to version 88 or later to resolve the issue.
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Firefox
Linuxmint
Ubuntu