#VU52337 Insecure Inherited Permissions in Mozilla Firefox and Firefox ESR - CVE-2021-23998
Published: April 19, 2021
Mozilla Firefox
Firefox ESR
Mozilla
Description
the vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to the way HTTP pages inherit a secure lock icon, when navigating from an HTTP page. A remote attacker can create a specially crafted webpage that through a series of complicated navigation will force the browser to display a secure lock icon on an unencrypted HTTP page.