PT-2021-7422 · Mozilla+4 · Firefox+4
Jonathan Kingston
·
Published
2021-09-07
·
Updated
2024-12-12
·
CVE-2021-38491
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 92
Description
The issue is related to mixed-content checks being unable to analyze opaque origins, leading to some mixed content being loaded. This could potentially allow a remote attacker to conduct spoofing attacks using a specially crafted link.
Recommendations
For versions prior to 92, update to version 92 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially vulnerable links to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Firefox
Linuxmint
Ubuntu