CVE Vulnerabilities

CVE-2020-15652

Origin Validation Error

Published: Aug 10, 2020 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
6.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla*79.0 (excluding)
FirefoxMozilla78.0 (including)78.1 (excluding)
Firefox_esrMozilla*68.11 (excluding)
ThunderbirdMozilla*68.11 (excluding)
ThunderbirdMozilla78.0 (including)78.1 (excluding)
Red Hat Enterprise Linux 6RedHatfirefox-0:68.11.0-1.el6_10*
Red Hat Enterprise Linux 6RedHatthunderbird-0:68.11.0-1.el6_10*
Red Hat Enterprise Linux 7RedHatfirefox-0:68.11.0-1.el7_8*
Red Hat Enterprise Linux 7RedHatthunderbird-0:68.11.0-1.el7_8*
Red Hat Enterprise Linux 8RedHatfirefox-0:68.11.0-1.el8_2*
Red Hat Enterprise Linux 8RedHatthunderbird-0:68.11.0-1.el8_2*
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsRedHatfirefox-0:68.11.0-1.el8_0*
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsRedHatthunderbird-0:68.11.0-1.el8_0*
Red Hat Enterprise Linux 8.1 Extended Update SupportRedHatfirefox-0:68.11.0-1.el8_1*
Red Hat Enterprise Linux 8.1 Extended Update SupportRedHatthunderbird-0:68.11.0-1.el8_1*
FirefoxUbuntubionic*
FirefoxUbuntudevel*
FirefoxUbuntufocal*
FirefoxUbuntugroovy*
FirefoxUbuntuhirsute*
FirefoxUbuntuimpish*
FirefoxUbuntujammy*
FirefoxUbuntukinetic*
FirefoxUbuntulunar*
FirefoxUbuntumantic*
FirefoxUbuntunoble*
FirefoxUbuntutrusty*
FirefoxUbuntuupstream*
FirefoxUbuntuxenial*
Mozjs38Ubuntubionic*
Mozjs38Ubuntuesm-apps/bionic*
Mozjs38Ubuntuupstream*
Mozjs52Ubuntubionic*
Mozjs52Ubuntuesm-apps/focal*
Mozjs52Ubuntuesm-infra/bionic*
Mozjs52Ubuntufocal*
Mozjs52Ubuntugroovy*
Mozjs52Ubuntuupstream*
Mozjs60Ubuntuupstream*
Mozjs68Ubuntuesm-infra/focal*
Mozjs68Ubuntufocal*
Mozjs68Ubuntugroovy*
Mozjs68Ubuntuupstream*
ThunderbirdUbuntubionic*
ThunderbirdUbuntufocal*
ThunderbirdUbuntutrusty*
ThunderbirdUbuntuupstream*
ThunderbirdUbuntuxenial*

References