CVE-2021-29958
published 2021-06-24CVE-2021-29958: When a download was initiated, the client did not check whether it was in normal or private browsing mode, which led to private mode cookies being shared in…
PriorityP416medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
0.67%
47.9th percentile
When a download was initiated, the client did not check whether it was in normal or private browsing mode, which led to private mode cookies being shared in normal browsing mode. This vulnerability affects Firefox for iOS < 34.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | < 34.0 | 34.0 |
| mozilla | firefox | — | — |
| mozilla | firefox_for_ios | >= unspecified < 34 | 34 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2021-29958: firefox - When a download was initiated, the client did not check whether it was in normal...
vendor_debian·2021·CVSS 4.3
CVE-2021-29958 [MEDIUM] CVE-2021-29958: firefox - When a download was initiated, the client did not check whether it was in normal...
When a download was initiated, the client did not check whether it was in normal or private browsing mode, which led to private mode cookies being shared in normal browsing mode. This vulnerability affects Firefox for iOS < 34.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2021-25: CVE-2021-29958
vendor_mozilla·CVSS 4.3
CVE-2021-29958 [MEDIUM] Mozilla Foundation Security Advisory 2021-25: CVE-2021-29958
Mozilla Foundation Security Advisory 2021-25
CVE: CVE-2021-29958
Product: Firefox for iOS
Impact: moderate
Fixed in: Firefox for iOS 34
GHSA
GHSA-5j3q-vmj5-h7fx: When a download was initiated, the client did not check whether it was in normal or private browsing mode, which led to private mode cookies being sha
ghsa_unreviewed·2022-05-24
CVE-2021-29958 [MEDIUM] CWE-668 GHSA-5j3q-vmj5-h7fx: When a download was initiated, the client did not check whether it was in normal or private browsing mode, which led to private mode cookies being sha
When a download was initiated, the client did not check whether it was in normal or private browsing mode, which led to private mode cookies being shared in normal browsing mode. This vulnerability affects Firefox for iOS < 34.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-06-24
Published