CVE Database
/

CVE-2020-12424

Back to search

CVE-2020-12424

Published: Jul 9, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of an origin that was previously granted permission; bypassing the prompt. This vulnerability affects Firefox < 78.

VendorProductVersions

Mozilla

Firefox

affected
unspecified - < 78

References

openSUSE-SU-2020:0983
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2020:1017
vendor-advisory
x_refsource_SUSE
GLSA-202007-10
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now