PT-2021-7431 · Mozilla · Firefox
Muneaki Nishimura
·
Published
2021-06-01
·
Updated
2022-07-12
·
CVE-2021-29958
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox for iOS versions prior to 34
Description
The issue is related to errors in authorization, where the client fails to differentiate between normal and private browsing modes. This leads to the sharing of private mode cookies in normal browsing mode, potentially allowing a remote attacker to gain unauthorized access to protected information.
Recommendations
For Firefox for iOS versions prior to 34, update to version 34 or later to resolve the issue. As a temporary workaround, consider avoiding the use of private browsing mode until the update is applied. Restrict access to sensitive information when using the browser in normal mode to minimize the risk of exploitation.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firefox