CVE-2020-12394 — Improper Input Validation in Mozilla Firefox
Severity
3.3LOWNVD
OSV8.1
EPSS
0.1%
top 64.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 26
Latest updateMay 24
Description
A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by selecting a different origin and removing focus from the input element. This vulnerability affects Firefox < 76.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 1.8 | Impact: 1.4
Affected Packages5 packages
🔴Vulnerability Details
4GHSA▶
GHSA-vp98-fg4h-f354: A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by selecting a different origin and↗2022-05-24
OSV▶
CVE-2020-12394: A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by selecting a different origin and↗2020-05-07
📋Vendor Advisories
5Debian▶
CVE-2020-12394: firefox - A logic flaw in our location bar implementation could have allowed a local attac...↗2020