CVE-2020-12393
published 2020-05-26CVE-2020-12393: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
1.01%
59.6th percentile
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 76.0 | 76.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 76 | 76 |
| mozilla | firefox_esr | < 68.8.0 | 68.8.0 |
| mozilla | firefox_esr | >= unspecified < 68.8 | 68.8 |
| mozilla | thunderbird | < 68.8.0 | 68.8.0 |
| mozilla | thunderbird | >= unspecified < 68.8.0 | 68.8.0 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Devtools' 'Copy as cURL' feature did not fully escape website-controlled data, potentially leading to command injection
vendor_redhat·2020-05-05·CVSS 7.8
CVE-2020-12393 [HIGH] CWE-552 Mozilla: Devtools' 'Copy as cURL' feature did not fully escape website-controlled data, potentially leading to command injection
Mozilla: Devtools' 'Copy as cURL' feature did not fully escape website-controlled data, potentially leading to command injection
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
The Mozilla Foundation Security Advisory describes this flaw as
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the websi
Debian
CVE-2020-12393: firefox - The 'Copy as cURL' feature of Devtools' network tab did not properly escape the ...
vendor_debian·2020·CVSS 7.8
CVE-2020-12393 [HIGH] CVE-2020-12393: firefox - The 'Copy as cURL' feature of Devtools' network tab did not properly escape the ...
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2020-16: CVE-2020-12393
vendor_mozilla·CVSS 7.8
CVE-2020-12393 [HIGH] Mozilla Foundation Security Advisory 2020-16: CVE-2020-12393
Mozilla Foundation Security Advisory 2020-16
CVE: CVE-2020-12393
Product: Firefox
Impact: high
Fixed in: Firefox 76
Mozilla
Mozilla Foundation Security Advisory 2020-18: CVE-2020-12393
vendor_mozilla·CVSS 7.8
CVE-2020-12393 [HIGH] Mozilla Foundation Security Advisory 2020-18: CVE-2020-12393
Mozilla Foundation Security Advisory 2020-18
CVE: CVE-2020-12393
Product: Thunderbird
Impact: critical
Fixed in: Thunderbird 68.8
Mozilla
Mozilla Foundation Security Advisory 2020-17: CVE-2020-12393
vendor_mozilla·CVSS 7.8
CVE-2020-12393 [HIGH] Mozilla Foundation Security Advisory 2020-17: CVE-2020-12393
Mozilla Foundation Security Advisory 2020-17
CVE: CVE-2020-12393
Product: Firefox ESR
Impact: critical
Fixed in: Firefox ESR 68.8
GHSA
GHSA-x932-mvm6-79m8: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website
ghsa_unreviewed·2022-05-24
CVE-2020-12393 [MEDIUM] CWE-74 GHSA-x932-mvm6-79m8: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
OSV
CVE-2020-12393: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website
osv·2020-05-26·CVSS 7.8
CVE-2020-12393 [HIGH] CVE-2020-12393: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
No detection rules found.
No public exploits indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1615471https://www.mozilla.org/security/advisories/mfsa2020-16/https://www.mozilla.org/security/advisories/mfsa2020-17/https://www.mozilla.org/security/advisories/mfsa2020-18/https://bugzilla.mozilla.org/show_bug.cgi?id=1615471https://www.mozilla.org/security/advisories/mfsa2020-16/https://www.mozilla.org/security/advisories/mfsa2020-17/https://www.mozilla.org/security/advisories/mfsa2020-18/
2020-05-26
Published