CVE-2020-12415Incorrect Default Permissions in Mozilla Firefox

Severity
6.5MEDIUMNVD
EPSS
0.4%
top 42.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 9
Latest updateMay 24

Description

When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory. This vulnerability affects Firefox < 78.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5mozilla/firefoxunspecified78
NVDmozilla/firefox< 78.0
Ubuntumozilla/firefox< 78.0.1+build1-0ubuntu0.16.04.1+2
Ubuntumozilla/thunderbird< 1:78.8.1+build1-0ubuntu0.18.04.1+1
NVDopensuse/leap15.1, 15.2+1

🔴Vulnerability Details

4
GHSA
GHSA-xp2p-6mv7-gcrx: When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory2022-05-24
CVEList
CVE-2020-12415: When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory2020-07-09
OSV
firefox vulnerabilities2020-07-02
OSV
CVE-2020-12415: When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory2020-07-01

📋Vendor Advisories

9
Oracle
Oracle Oracle Communications Risk Matrix: IDIH (Apache POI) — CVE-2019-124152020-10-15
Red Hat
Mozilla: AppCache manifest poisoning due to url encoded character processing2020-07-16
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Application Service Level Mgmt (Apache POI) — CVE-2019-124152020-07-15
Ubuntu
Firefox vulnerabilities2020-07-02
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Office Open document processor (Apache POI) — CVE-2019-124152020-04-15

💬Community

1
Bugzilla
CVE-2020-12415 Mozilla: AppCache manifest poisoning due to url encoded character processing2020-09-03
CVE-2020-12415 — Incorrect Default Permissions | cvebase