Security restrictions bypass in Mozilla Firefox - CVE-2021-29974
Published: July 13, 2021
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to application allows to override HSTS error, when network partitioning was enabled. As a result of Enhanced Tracking Protection settings, a TLS error page would allow the user to override an error on a domain which had specified HTTP Strict Transport Security.
Affected software
Arch Linux
Gentoo Linux
Ubuntu
firefox (Ubuntu package)
How to mitigate CVE-2021-29974
firefox (Ubuntu package) - addressed in versions 90.0+build1-0ubuntu0.18.04.1, 90.0+build1-0ubuntu0.20.04.1, 90.0+build1-0ubuntu0.20.10.1, 90.0+build1-0ubuntu0.21.04.1