PT-2021-7431 · Mozilla · Firefox

Muneaki Nishimura

·

Published

2021-06-01

·

Updated

2022-07-12

·

CVE-2021-29958

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Firefox for iOS versions prior to 34
Description The issue is related to errors in authorization, where the client fails to differentiate between normal and private browsing modes. This leads to the sharing of private mode cookies in normal browsing mode, potentially allowing a remote attacker to gain unauthorized access to protected information.
Recommendations For Firefox for iOS versions prior to 34, update to version 34 or later to resolve the issue. As a temporary workaround, consider avoiding the use of private browsing mode until the update is applied. Restrict access to sensitive information when using the browser in normal mode to minimize the risk of exploitation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06174
CVE-2021-29958

Affected Products

Firefox