CVE-2020-15677
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually…
Does this matter?
Lower severity and a low EPSS score (1.64%). Track it; it rarely justifies an emergency change on its own.
Description
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.64% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- mozilla/firefox · mozilla/firefox esr · mozilla/thunderbird · debian/debian linux · opensuse/leap
- Source
- security@mozilla.org
References
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00074.htmlBroken Link, Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00077.htmlBroken Link, Mailing List, Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1641487Issue Tracking, Permissions Required, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2020/10/msg00020.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202010-02Third Party Advisory
- https://www.debian.org/security/2020/dsa-4770Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-42/Release Notes, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-43/Release Notes, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-44/Release Notes, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00074.htmlBroken Link, Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00077.htmlBroken Link, Mailing List, Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1641487Issue Tracking, Permissions Required, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2020/10/msg00020.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202010-02Third Party Advisory
- https://www.debian.org/security/2020/dsa-4770Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-42/Release Notes, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-43/Release Notes, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-44/Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.