CVE-2020-15651
published 2020-08-10CVE-2020-15651: A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This…
PriorityP417medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.58%
44.3th percentile
A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This vulnerability affects Firefox for iOS < 28.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | < 28.0 | 28.0 |
| mozilla | firefox | — | — |
| mozilla | firefox_for_ios | >= unspecified < 28 | 28 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2020-15651: firefox - A unicode RTL order character in the downloaded file name can be used to change ...
vendor_debian·2020·CVSS 4.3
CVE-2020-15651 [MEDIUM] CVE-2020-15651: firefox - A unicode RTL order character in the downloaded file name can be used to change ...
A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This vulnerability affects Firefox for iOS < 28.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2020-34: CVE-2020-15651
vendor_mozilla·CVSS 4.3
CVE-2020-15651 [MEDIUM] Mozilla Foundation Security Advisory 2020-34: CVE-2020-15651
Mozilla Foundation Security Advisory 2020-34
CVE: CVE-2020-15651
Product: Firefox for iOS
Impact: low
Fixed in: Firefox for iOS 28
GHSA
GHSA-5p65-3pv7-7gq2: A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extensi
ghsa_unreviewed·2022-05-24
CVE-2020-15651 [MEDIUM] CWE-20 GHSA-5p65-3pv7-7gq2: A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extensi
A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This vulnerability affects Firefox for iOS < 28.
No detection rules found.
No public exploits indexed.
Bugzilla
Download Feature: unicode RTLO char can fake the file extension
bugzilla·2020-06-29
Download Feature: unicode RTLO char can fake the file extension
Download Feature: unicode RTLO char can fake the file extension
Created attachment 9160077
regedtgpj.exe
Summary:
I have found a vulnerability of RTLO in RTLO in firefox browser’s download feature
Step to Reproduce:
1. Change the filename to: malicious.
For example: regedtjpg.exe
2. When the browser download feature fails to to parse the character perfectly, the filename will be changed to regedtexe.jpg
Impact:
There isn't a good way to utilize to cause a damage in ios, but the vulnerability is there for unkonwn Subsequent attack
system detail:
firefox 27.0(18428)
OS iphone 13.5.1
The Reference:
1. opera Mini for Android(CVE-2019–18624): http://www.firstsight.me/2019/10/illegal-rendered-at-download-feature-in-several-apps-including-opera-mini-that-lead-to-extension-manipulation-with-rtl
Bugzilla
CVE-2020-10689 che: pods in kubernetes cluster can bypass JWT proxy and send unauthenticated requests to workspace pods
bugzilla·2020-03-24·CVSS 6.4
CVE-2020-10689 [MEDIUM] CVE-2020-10689 che: pods in kubernetes cluster can bypass JWT proxy and send unauthenticated requests to workspace pods
CVE-2020-10689 che: pods in kubernetes cluster can bypass JWT proxy and send unauthenticated requests to workspace pods
On Eclipse Che up to version 7.8.x any pod running in a Kubernetes cluster is able to send unauthenticated requests to Eclipse Che Workspaces pods bypassing the JWT proxy. This implies an user can send requests to another user's machine-exec container getting access to it, bypassing the JWT proxy.
For an attack be considered successful, the attacker needs to know the ip or name of targeted service and the namespace where workspaces are running.
This flaw was fixed on Eclipse Che 7.9.0.
https://github.com/eclipse/che/issues/15651
Discussion:
Acknowledgments:
Name: Mario Loriedo (Red Hat)
---
Upstream commits for this issue:
https://github.com/eclipse/che-theia/comm
2020-08-10
Published