CVE-2020-15647Sensitive Information Exposure in Mozilla Firefox FOR

Severity
7.4HIGHNVD
EPSS
0.2%
top 51.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 10
Latest updateMay 24

Description

A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. This vulnerability affects Firefox for < Android.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:NExploitability: 2.8 | Impact: 4.0

Affected Packages4 packages

NVDmozilla/firefox< 68.10.1
CVEListV5mozilla/firefox_forunspecifiedAndroid
mozillamozilla/firefox

🔴Vulnerability Details

1
GHSA
GHSA-7qq3-vgfq-7f3m: A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disc2022-05-24

📋Vendor Advisories

2
Debian
CVE-2020-15647: firefox - A Content Provider in Firefox for Android allowed local files accessible by the ...2020
Mozilla
Mozilla Foundation Security Advisory 2020-27: CVE-2020-15647