CVE-2020-6811Command Injection in Mozilla Firefox

Severity
8.8HIGHNVD
OSV6.5
EPSS
1.4%
top 19.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25
Latest updateMay 24

Description

The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified74+1
NVDmozilla/firefox< 74.0
CVEListV5mozilla/firefox_esrunspecified68.6
NVDmozilla/firefox_esr< 68.6.0
Ubuntumozilla/firefox< 74.0+build3-0ubuntu0.16.04.1+1

Also affects: Ubuntu Linux 16.04, 18.04, 19.10

🔴Vulnerability Details

6
GHSA
GHSA-ffwg-6pqv-h33r: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website2022-05-24
OSV
thunderbird vulnerabilities2020-04-21
OSV
thunderbird vulnerabilities2020-04-13
OSV
CVE-2020-6811: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website2020-03-25
CVEList
CVE-2020-6811: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website2020-03-25

📋Vendor Advisories

8
Ubuntu
Thunderbird vulnerabilities2020-04-21
Ubuntu
Thunderbird vulnerabilities2020-04-13
Ubuntu
Firefox vulnerabilities2020-03-11
Red Hat
Mozilla: Devtools' 'Copy as cURL' feature did not fully escape website-controlled data, potentially leading to command injection2020-03-10
Debian
CVE-2020-6811: firefox - The 'Copy as cURL' feature of Devtools' network tab did not properly escape the ...2020

💬Community

1
Bugzilla
CVE-2020-6811 Mozilla: Devtools' 'Copy as cURL' feature did not fully escape website-controlled data, potentially leading to command injection2020-03-10
CVE-2020-6811 — Command Injection in Mozilla Firefox | cvebase