CVE-2021-23955UI Misrepresentation / Clickjacking in Mozilla Firefox

Severity
6.1MEDIUMNVD
EPSS
0.1%
top 66.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 26
Latest updateMay 24

Description

The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks. This vulnerability affects Firefox < 85.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages5 packages

debiandebian/firefox< firefox 85.0-1 (sid)
CVEListV5mozilla/firefox< 85
NVDmozilla/firefox< 85.0
Ubuntumozilla/firefox< 85.0+build1-0ubuntu0.16.04.1+2
mozillamozilla/firefox

🔴Vulnerability Details

2
GHSA
GHSA-jf2q-69fh-6qqg: The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks2022-05-24
OSV
CVE-2021-23955: The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks2021-01-26

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2021-02-01
Debian
CVE-2021-23955: firefox - The browser could have been confused into transferring a pointer lock state into...2021
Mozilla
Mozilla Foundation Security Advisory 2021-03: CVE-2021-23955