Permissions, Privileges, and Access Controls in Mozilla Firefox - CVE-2020-6809
Published: March 10, 2020 / Updated: March 10, 2020
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to Web Extension with all-urls permissions is allowed to access local files. A remote attacker can trick the victim into installing a malicious browser extension and gain access to sensitive information on the system.
Affected software
Arch Linux
firefox (Ubuntu package)
firefox (Alpine package)
Cloud App Management V2018
How to mitigate CVE-2020-6809
firefox (Ubuntu package) - addressed in versions 74.0+build3-0ubuntu0.16.04.1, 74.0+build3-0ubuntu0.18.04.1, 74.0+build3-0ubuntu0.19.10.1
firefox (Alpine package) - update to 74.0-r0
Cloud App Management V2018 - update to 2020.1.0