CVE-2016-2820Improper Access Control in Firefox

Severity
4.3MEDIUMNVD
OSV8.8
EPSS
0.4%
top 37.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 30
Latest updateMay 17

Description

The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

Ubuntumozilla/firefox< 46.0+build5-0ubuntu0.14.04.2+3
NVDmozilla/firefox45.0.2
debiandebian/firefox< firefox 46.0-1 (sid)
debiandebian/firefox-esr< firefox 46.0-1 (sid)

🔴Vulnerability Details

4
GHSA
GHSA-9f9w-vwq3-c9fh: The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 462022-05-17
OSV
firefox regression2016-05-19
OSV
firefox vulnerabilities2016-04-27
OSV
CVE-2016-2820: The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 462016-04-27

📋Vendor Advisories

5
Ubuntu
Firefox regression2016-05-19
Ubuntu
Oxygen-GTK3 update2016-05-02
Ubuntu
Firefox vulnerabilities2016-04-27
Red Hat
Mozilla: Firefox Health Reports could accept events from untrusted domains (MFSA 2016-48)2016-04-26
Debian
CVE-2016-2820: firefox - The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Fi...2016

💬Community

1
Bugzilla
CVE-2016-2820 Mozilla: Firefox Health Reports could accept events from untrusted domains (MFSA 2016-48)2016-04-25