CVE-2020-26967
Last modified
CVE-2020-26967 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. When listening for page changes with a Mutation Observer, a malicious web page could confuse Firefox Screenshots into interacting with elements other than those that it injected into the page. This would lead to internal errors and unexpected behavior in the Screenshots code. EPSS estimates a 0.84% chance of exploitation in the next 30 days.
Description
When listening for page changes with a Mutation Observer, a malicious web page could confuse Firefox Screenshots into interacting with elements other than those that it injected into the page. This would lead to internal errors and unexpected behavior in the Screenshots code. This vulnerability affects Firefox < 83.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 83.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1665820Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-50/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1665820Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-50/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-26967?
How severe is CVE-2020-26967?
How do I fix CVE-2020-26967?
Are you affected by CVE-2020-26967?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
