Vulnerability CVE-2021-23968: Information

Description

If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.

Severity: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Published: Feb. 26, 2021
Modified: May 27, 2022
Error type identifier: CWE-209

Fixed packages

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://bugzilla.mozilla.org/show_bug.cgi?id=1687342
  • Issue Tracking
  • Permissions Required
  • Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2021-08/
  • Release Notes
  • Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2021-09/
  • Release Notes
  • Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2021-07/
  • Release Notes
  • Vendor Advisory
[debian-lts-announce] 20210301 [SECURITY] [DLA 2578-1] thunderbird security update
  • Mailing List
  • Third Party Advisory
DSA-4866
  • Third Party Advisory
GLSA-202104-09
  • Third Party Advisory
GLSA-202104-10
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
      End excliding
      86.0

      cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
      End excliding
      78.8

      cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
      End excliding
      78.8

      Configuration 2

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*