CVE-2020-15677

CVSS v3.1 6.1 (Medium)
61% Progress
CVSS v2.0 5.8 (Medium)
58% Progress
EPSS 0.35 % (72th)
0.35% Progress
Affected Products 5
Advisories 30

By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.

Weaknesses
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2020-10-01 19:15:13
(4 years ago)
Updated Date
2022-11-16 15:15:40
(22 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 81.0 version cpe:2.3:a:mozilla:firefox < 81.0
  Mozilla Firefox Esr prior 78.3 version cpe:2.3:a:mozilla:firefox_esr < 78.3
  Mozilla Thunderbird prior 78.3 version cpe:2.3:a:mozilla:thunderbird < 78.3

Configuration #2

    CPE23 From Up To
  Debian Linux 9.0 cpe:2.3:o:debian:debian_linux:9.0
  Debian Linux 10.0 cpe:2.3:o:debian:debian_linux:10.0

Configuration #3

    CPE23 From Up To
  Opensuse Leap 15.1 cpe:2.3:o:opensuse:leap:15.1
  Opensuse Leap 15.2 cpe:2.3:o:opensuse:leap:15.2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...