#VU48463 Permissions, Privileges, and Access Controls in Mozilla Firefox and Firefox ESR - CVE-2020-26958

 

#VU48463 Permissions, Privileges, and Access Controls in Mozilla Firefox and Firefox ESR - CVE-2020-26958

Published: November 17, 2020


Vulnerability identifier: #VU48463
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2020-26958
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Mozilla Firefox
Firefox ESR
Software vendor:
Mozilla

Description

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due Firefox does not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. A remote attacker can exploit this behavior to perform a cross-site script inclusion vulnerability or bypass implemented Content Security Policy restrictions.


Remediation

Install updates from vendor's website.

External links