#VU49022 Information disclosure in Mozilla Firefox and Firefox ESR - CVE-2020-35111
Published: December 15, 2020
Mozilla Firefox
Firefox ESR
Mozilla
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the proxy.onRequest API does not use proxy when viewing source code of the web application. A remote attacker, who controls the web server can obtain user's real IP address, if the user decides to view the web application source code while behind a proxy server.