CVE-2020-26976
published 2021-01-07CVE-2020-26976: When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request…
PriorityP430medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
1.56%
72.2th percentile
When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox | < firefox 84.0-1 (sid) | firefox 84.0-1 (sid) |
| debian | firefox-esr | < firefox 84.0-1 (sid) | firefox 84.0-1 (sid) |
| debian | thunderbird | < firefox 84.0-1 (sid) | firefox 84.0-1 (sid) |
| mozilla | firefox | < 84.0 | 84.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 84.0+build3-0ubuntu0.16.04.1 | 84.0+build3-0ubuntu0.16.04.1 |
| mozilla | firefox | >= 0 < 84.0+build3-0ubuntu0.18.04.1 | 84.0+build3-0ubuntu0.18.04.1 |
| mozilla | firefox | >= 0 < 84.0+build3-0ubuntu0.20.04.1 | 84.0+build3-0ubuntu0.20.04.1 |
| mozilla | firefox | >= unspecified < 84 | 84 |
| mozilla | thunderbird | >= 0 < 1:78.7.0-1 | 1:78.7.0-1 |
| mozilla | thunderbird | >= 0 < 1:78.7.0-1 | 1:78.7.0-1 |
| mozilla | thunderbird | >= 0 < 1:78.7.0-1 | 1:78.7.0-1 |
| mozilla | thunderbird | >= 0 < 1:78.7.0-1 | 1:78.7.0-1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.5MEDIUM
vendor_ubuntu8.8HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-77q8-crvw-8w9q: When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted th
ghsa_unreviewed·2022-05-24
CVE-2020-26976 [MEDIUM] GHSA-77q8-crvw-8w9q: When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted th
When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.
OSV
CVE-2020-26976: When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted th
osv·2021-01-07·CVSS 6.5
CVE-2020-26976 [MEDIUM] CVE-2020-26976: When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted th
When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.
OSV
firefox vulnerabilities
osv·2020-12-15·CVSS 6.5
CVE-2020-16042 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information, bypass the CSS sanitizer, bypass security restrictions,
spoof the URL bar, or execute arbitrary code. (CVE-2020-16042,
CVE-2020-26971, CVE-2020-26972, CVE-2020-26793, CVE-2020-26974,
CVE-2020-26976, CVE-2020-26978, CVE-2020-26979,
CVE-2020-35113, CVE-2020-35114)
It was discovered that the proxy.onRequest API did not catch
view-source URLs. If a user were tricked in to installing an
extension with the proxy permission and opening View Source, an
attacker could potentially exploit this to obtain sensitive
information. (CVE-2020-35111)
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2021-02-16·CVSS 8.8
CVE-2020-15685 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, or execute arbitrary code. (CVE-2020-26976,
CVE-2021-23953, CVE-2021-23954, CVE-2021-23960, CVE-2021-23964)
It was discovered that responses received during the plaintext phase of
the STARTTLS connection setup were subsequently evaluated during the
encrypted session. A person in the middle could potentially exploit this
to perform a response injection attack. (CVE-2020-15685)
Instructions: After a standard system update you need to restart Thunderbi
Red Hat
Mozilla: HTTPS pages could have been intercepted by a registered service worker when they should not have been
vendor_redhat·2021-01-26·CVSS 6.5
CVE-2020-26976 [MEDIUM] CWE-200 Mozilla: HTTPS pages could have been intercepted by a registered service worker when they should not have been
Mozilla: HTTPS pages could have been intercepted by a registered service worker when they should not have been
When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.
The Mozilla Foundation Security Advisory describes this flaw as:
When a HTTPS page was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing.
Package: firefox (Red Hat Enterprise Linux 6) - Out of support scop
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2020-12-15·CVSS 6.5
CVE-2020-26971 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information, bypass the CSS sanitizer, bypass security restrictions,
spoof the URL bar, or execute arbitrary code. (CVE-2020-16042,
CVE-2020-26971, CVE-2020-26972, CVE-2020-26793, CVE-2020-26974,
CVE-2020-26976, CVE-2020-26978, CVE-2020-26979,
CVE-2020-35113, CVE-2020-35114)
It was discovered that the proxy.onRequest API did not catch
view-source URLs. If a user were tricked in to installing an
extension with the proxy permission and opening View So
Debian
CVE-2020-26976: firefox - When a HTTPS pages was embedded in a HTTP page, and there was a service worker r...
vendor_debian·2020·CVSS 6.5
CVE-2020-26976 [MEDIUM] CVE-2020-26976: firefox - When a HTTPS pages was embedded in a HTTP page, and there was a service worker r...
When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.
Scope: local
sid: resolved (fixed in 84.0-1)
Mozilla
Mozilla Foundation Security Advisory 2021-05: CVE-2020-26976
vendor_mozilla·CVSS 6.5
CVE-2020-26976 [MEDIUM] Mozilla Foundation Security Advisory 2021-05: CVE-2020-26976
Mozilla Foundation Security Advisory 2021-05
CVE: CVE-2020-26976
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 78.7
Mozilla
Mozilla Foundation Security Advisory 2020-54: CVE-2020-26976
vendor_mozilla·CVSS 6.5
CVE-2020-26976 [MEDIUM] Mozilla Foundation Security Advisory 2020-54: CVE-2020-26976
Mozilla Foundation Security Advisory 2020-54
CVE: CVE-2020-26976
Product: Firefox
Impact: high
Fixed in: Firefox 84
Mozilla
Mozilla Foundation Security Advisory 2021-04: CVE-2020-26976
vendor_mozilla·CVSS 6.5
CVE-2020-26976 [MEDIUM] Mozilla Foundation Security Advisory 2021-04: CVE-2020-26976
Mozilla Foundation Security Advisory 2021-04
CVE: CVE-2020-26976
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 78.7
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1674343https://lists.debian.org/debian-lts-announce/2021/02/msg00001.htmlhttps://lists.debian.org/debian-lts-announce/2021/02/msg00002.htmlhttps://security.gentoo.org/glsa/202102-02https://www.debian.org/security/2021/dsa-4840https://www.debian.org/security/2021/dsa-4842https://www.mozilla.org/security/advisories/mfsa2020-54/https://bugzilla.mozilla.org/show_bug.cgi?id=1674343https://lists.debian.org/debian-lts-announce/2021/02/msg00001.htmlhttps://lists.debian.org/debian-lts-announce/2021/02/msg00002.htmlhttps://security.gentoo.org/glsa/202102-02https://www.debian.org/security/2021/dsa-4840https://www.debian.org/security/2021/dsa-4842https://www.mozilla.org/security/advisories/mfsa2020-54/
2021-01-07
Published