CVE-2020-15677Open Redirect in Mozilla Firefox

CWE-601Open Redirect11 documents9 sources
Severity
6.1MEDIUMNVD
EPSS
0.5%
top 32.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 1
Latest updateMay 24

Description

By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages8 packages

CVEListV5mozilla/firefoxunspecified81
NVDmozilla/firefox< 81.0
CVEListV5mozilla/firefox_esrunspecified78.3
NVDopensuse/leap15.1, 15.2+1

Also affects: Debian Linux 10.0, 9.0

🔴Vulnerability Details

3
GHSA
GHSA-c2xm-2fm6-9338: By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the o2022-05-24
CVEList
CVE-2020-15677: By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the o2020-10-01
OSV
CVE-2020-15677: By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the o2020-10-01

📋Vendor Advisories

6
Ubuntu
Firefox vulnerabilities2020-09-28
Red Hat
Mozilla: Download origin spoofing via redirect2020-09-22
Debian
CVE-2020-15677: firefox - By exploiting an Open Redirect vulnerability on a website, an attacker could hav...2020
Mozilla
Mozilla Foundation Security Advisory 2020-43: CVE-2020-15677
Mozilla
Mozilla Foundation Security Advisory 2020-44: CVE-2020-15677

💬Community

1
Bugzilla
CVE-2020-15677 Mozilla: Download origin spoofing via redirect2020-09-22
CVE-2020-15677 — Open Redirect in Mozilla Firefox | cvebase