Severity
5.5MEDIUMNVD
OSV8.1
EPSS
0.2%
top 63.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 26
Latest updateMay 24

Description

The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in the disclosure of local files. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified76
NVDmozilla/firefox< 76.0
CVEListV5mozilla/firefox_esrunspecified68.8
NVDmozilla/firefox_esr< 68.8.0
Ubuntumozilla/firefox< 76.0.1+build1-0ubuntu0.16.04.1+5

Also affects: Ubuntu Linux 16.04, 18.04, 19.10, 20.04

🔴Vulnerability Details

6
GHSA
GHSA-f75r-qhf4-x3wr: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website2022-05-24
OSV
CVE-2020-12392: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website2020-05-26
OSV
thunderbird vulnerabilities2020-05-26
CVEList
CVE-2020-12392: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website2020-05-26
OSV
firefox regression2020-05-12

📋Vendor Advisories

8
Ubuntu
Thunderbird vulnerabilities2020-05-26
Ubuntu
Firefox regression2020-05-12
Ubuntu
Firefox vulnerabilities2020-05-07
Red Hat
Mozilla: Arbitrary local file access with 'Copy as cURL'2020-05-05
Debian
CVE-2020-12392: firefox - The 'Copy as cURL' feature of Devtools' network tab did not properly escape the ...2020

💬Community

1
Bugzilla
CVE-2020-12392 Mozilla: Arbitrary local file access with 'Copy as cURL'2020-05-05
CVE-2020-12392 — Path Traversal in Mozilla Firefox | cvebase