CVE-2020-15668 — Improper Locking in Mozilla Firefox
Severity
4.3MEDIUMNVD
EPSS
0.2%
top 57.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 1
Latest updateMay 24
Description
A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4
Affected Packages4 packages
🔴Vulnerability Details
4GHSA▶
GHSA-6f2w-35qh-6j7j: A lock was missing when accessing a data structure and importing certificate information into the trust database↗2022-05-24
CVEList▶
CVE-2020-15668: A lock was missing when accessing a data structure and importing certificate information into the trust database↗2020-10-01
OSV▶
CVE-2020-15668: A lock was missing when accessing a data structure and importing certificate information into the trust database↗2020-08-26
📋Vendor Advisories
4Debian▶
CVE-2020-15668: firefox - A lock was missing when accessing a data structure and importing certificate inf...↗2020