Vulnerability CVE-2020-15652: Information

Description

By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1.

Severity: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Published: Aug. 10, 2020
Modified: Dec. 7, 2022
Error type identifier: CWE-346

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
firefoxsisyphus79.0-alt1125.0.2-alt1ALT-PU-2020-2598-1256176Fixed
firefoxp1079.0-alt1118.0.2-alt0.p10.1ALT-PU-2020-2598-1256176Fixed
firefoxp980.0.1-alt0.1.p9105.0.1-alt0.c9.1ALT-PU-2020-3442-1262506Fixed
firefoxc10f179.0-alt1112.0.2-alt0.p10.1ALT-PU-2020-2598-1256176Fixed
firefoxc9f293.0-alt0.p9.1105.0.1-alt0.c9.1ALT-PU-2021-3368-1288792Fixed
firefox-esrsisyphus78.1.0-alt1115.10.0-alt1ALT-PU-2020-2466-1255488Fixed
firefox-esrp1091.1.0-alt1115.10.0-alt1ALT-PU-2021-2881-1284980Fixed
firefox-esrp978.3.0-alt0.1.p9102.11.0-alt0.c9.1ALT-PU-2020-2933-1254920Fixed
firefox-esrc10f191.1.0-alt1115.9.1-alt0.c10.1ALT-PU-2021-2881-1284980Fixed
firefox-esrc9f291.3.0-alt1.c9.1102.12.0-alt0.c9.1ALT-PU-2021-3369-1288792Fixed
thunderbirdsisyphus78.1.1-alt1115.9.0-alt1ALT-PU-2020-2709-1256264Fixed
thunderbirdp1078.1.1-alt1115.9.0-alt1ALT-PU-2020-2709-1256264Fixed
thunderbirdp978.3.1-alt1102.11.0-alt0.c9.1ALT-PU-2020-2934-1254920Fixed
thunderbirdc10f178.1.1-alt1115.9.0-alt0.c10.1ALT-PU-2020-2709-1256264Fixed
thunderbirdc9f278.7.0-alt0.1.c9102.11.0-alt0.c9.1ALT-PU-2021-1369-1264611Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
      End excliding
      79.0

      cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
      End excliding
      68.11

      cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
      End excliding
      68.11

      cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
      Start including
      78.0
      End excliding
      78.1

      cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
      Start including
      78.0
      End excliding
      78.1

      Configuration 2

      cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*