CVE-2021-24000

CVSS v3.1 3.1 (Low)
31% Progress
CVSS v2.0 2.6 (Low)
26% Progress
EPSS 0.08 % (37th)
0.08% Progress
Affected Products 1
Advisories 4

A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when they believed they were on a separate tab. In conjunction with certain elements (such as <input type="file">) this could have led to an attack where a user was confused about the origin of the webpage and potentially disclosed information they did not intend to. This vulnerability affects Firefox < 88.

Weaknesses
CWE-NVD-Other
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2021-06-24 14:15:09
(3 years ago)
Updated Date
2021-07-01 18:25:01
(3 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 88.0 version cpe:2.3:a:mozilla:firefox < 88.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...