CVE Database
/

CVE-2021-29974

Back to search

CVE-2021-29974

Published: Aug 5, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

When network partitioning was enabled, e.g. as a result of Enhanced Tracking Protection settings, a TLS error page would allow the user to override an error on a domain which had specified HTTP Strict Transport Security (which implies that the error should not be override-able.) This issue did not affect the network connections, and they were correctly upgraded to HTTPS automatically. This vulnerability affects Firefox < 90.

VendorProductVersions

Mozilla

Firefox

affected
unspecified - < 90

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now