Spoofing attack in Mozilla Firefox - CVE-2020-12394
Published: May 5, 2020
Vulnerability identifier: #VU27537
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12394
CWE-ID: CWE-451
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform spoofing attack.
The vulnerability exists due to a logic flaw in the location bar implementation. A local user can spoof the current location by selecting a different origin and removing focus from the input element.
Affected software
Mozilla Firefox
Arch Linux
Gentoo Linux
firefox (Ubuntu package)
firefox (Alpine package)
Arch Linux
Gentoo Linux
firefox (Ubuntu package)
firefox (Alpine package)
How to mitigate CVE-2020-12394
Install updates from vendor's website.
Mozilla Firefox - update to 76.0
firefox (Ubuntu package) - addressed in versions 76.0+build2-0ubuntu0.16.04.1, 76.0+build2-0ubuntu0.18.04.1, 76.0+build2-0ubuntu0.19.10.1, 76.0+build2-0ubuntu0.20.04.1, 76.0.1+build1-0ubuntu0.16.04.1, 76.0.1+build1-0ubuntu0.18.04.1, 76.0.1+build1-0ubuntu0.19.10.1, 76.0.1+build1-0ubuntu0.20.04.1
firefox (Alpine package) - update to 76.0-r0
firefox (Ubuntu package) - addressed in versions 76.0+build2-0ubuntu0.16.04.1, 76.0+build2-0ubuntu0.18.04.1, 76.0+build2-0ubuntu0.19.10.1, 76.0+build2-0ubuntu0.20.04.1, 76.0.1+build1-0ubuntu0.16.04.1, 76.0.1+build1-0ubuntu0.18.04.1, 76.0.1+build1-0ubuntu0.19.10.1, 76.0.1+build1-0ubuntu0.20.04.1
firefox (Alpine package) - update to 76.0-r0