Permissions, Privileges, and Access Controls in Mozilla Firefox - CVE-2020-6823
Published: April 7, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect processing of extension permissions. A malicious extension could have called browser.identity.launchWebAuthFlow,
controlling the redirect_uri, and through the Promise returned, obtain
the Auth code and gain access to the user's account at the service
provider.
Affected software
Gentoo Linux
Arch Linux
firefox (Ubuntu package)
firefox (Alpine package)
How to mitigate CVE-2020-6823
firefox (Ubuntu package) - addressed in versions 75.0+build3-0ubuntu0.16.04.1, 75.0+build3-0ubuntu0.18.04.1, 75.0+build3-0ubuntu0.19.10.1
firefox (Alpine package) - update to 75.0-r0