#VU29452 Input validation error in Mozilla Firefox - CVE-2020-12417
Published: July 2, 2020 / Updated: July 31, 2020
Mozilla Firefox
Mozilla
Description
The vulnerability allows a remote attacker to perform cache poisoning attack.
The vulnerability exists due to an error when processing the %2F character in a manifest URL, which results in Firefox's AppCache behavior to become confused and allowe a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory.