CVE-2020-26958Cross-site Scripting in Mozilla Firefox

CWE-79Cross-site Scripting12 documents8 sources
Severity
6.1MEDIUMNVD
EPSS
0.5%
top 35.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 9
Latest updateMay 24

Description

Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages7 packages

CVEListV5mozilla/firefox< 83
NVDmozilla/firefox< 83.0
CVEListV5mozilla/firefox_esr< 78.5
CVEListV5mozilla/thunderbird< 78.5

🔴Vulnerability Details

3
GHSA
GHSA-3qgm-cw58-7h2p: Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker2022-05-24
OSV
CVE-2020-26958: Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker2020-12-09
CVEList
CVE-2020-26958: Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker2020-12-09

📋Vendor Advisories

8
Ubuntu
Thunderbird vulnerabilities2020-11-25
Ubuntu
Firefox vulnerabilities2020-11-19
Ubuntu
Firefox vulnerabilities2020-11-18
Red Hat
Mozilla: Requests intercepted through ServiceWorkers lacked MIME type restrictions2020-11-17
Debian
CVE-2020-26958: firefox - Firefox did not block execution of scripts with incorrect MIME types when the re...2020
CVE-2020-26958 — Cross-site Scripting in Mozilla | cvebase