CVE-2020-15666Information Exposure via Error Message in Mozilla Firefox

Severity
6.5MEDIUMNVD
OSV4.7
EPSS
0.4%
top 40.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 1
Latest updateMay 24

Description

When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message. This level of information leakage is inconsistent with the standardized onerror/onsuccess disclosure and can lead to inferring login status to services or device discovery on a local network among other attacks. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5mozilla/firefox_for_androidunspecified80
CVEListV5mozilla/firefoxunspecified80
NVDmozilla/firefox< 80.0
Ubuntumozilla/firefox< 80.0+build2-0ubuntu0.16.04.1+2

🔴Vulnerability Details

5
GHSA
GHSA-5jw8-m77m-3jjm: When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc2022-05-24
CVEList
CVE-2020-15666: When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc2020-10-01
OSV
firefox regressions2020-09-03
OSV
firefox vulnerabilities2020-08-26
OSV
CVE-2020-15666: When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc2020-08-26

📋Vendor Advisories

4
Ubuntu
Firefox vulnerabilities2020-08-26
Debian
CVE-2020-15666: firefox - When trying to load a non-video in an audio/video context the exact status code ...2020
Mozilla
Mozilla Foundation Security Advisory 2020-36: CVE-2020-15666
Mozilla
Mozilla Foundation Security Advisory 2020-39: CVE-2020-15666
CVE-2020-15666 — Information Exposure via Error Message | cvebase