CVE-2020-15664Incorrect Authorization in Mozilla Firefox

Severity
6.5MEDIUMNVD
OSV4.7
EPSS
0.4%
top 41.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 1
Latest updateMay 24

Description

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, Firefox ESR < 78.2, and Firefox for Android < 80.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages9 packages

CVEListV5mozilla/firefox_for_androidunspecified80
CVEListV5mozilla/firefoxunspecified80
NVDmozilla/firefox78.078.2+1
CVEListV5mozilla/firefox_esrunspecified68.12+1
NVDmozilla/firefox_esr< 68.12

🔴Vulnerability Details

5
GHSA
GHSA-f4gc-pc7j-rfxr: By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object wh2022-05-24
CVEList
CVE-2020-15664: By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object wh2020-10-01
OSV
CVE-2020-15664: By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object wh2020-10-01
OSV
firefox regressions2020-09-03
OSV
firefox vulnerabilities2020-08-26

📋Vendor Advisories

9
Ubuntu
Firefox vulnerabilities2020-08-26
Red Hat
Mozilla: Attacker-induced prompt for extension installation2020-08-25
Debian
CVE-2020-15664: firefox - By holding a reference to the eval() function from an about:blank window, a mali...2020
Mozilla
Mozilla Foundation Security Advisory 2020-38: CVE-2020-15664
Mozilla
Mozilla Foundation Security Advisory 2020-36: CVE-2020-15664

💬Community

1
Bugzilla
CVE-2020-15664 Mozilla: Attacker-induced prompt for extension installation2020-08-26
CVE-2020-15664 — Incorrect Authorization in Mozilla | cvebase