Vulnerability Description
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 81.0 |
| Mozilla | Firefox Esr | < 78.3 |
| Mozilla | Thunderbird | < 78.3 |
| Debian | Debian Linux | 9.0 |
| Opensuse | Leap | 15.1 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00074.htmlBroken LinkMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00077.htmlBroken LinkMailing ListThird Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1641487Issue TrackingPermissions RequiredVendor Advisory
- https://lists.debian.org/debian-lts-announce/2020/10/msg00020.htmlMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202010-02Third Party Advisory
- https://www.debian.org/security/2020/dsa-4770Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-42/Release NotesVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-43/Release NotesVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-44/Release NotesVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00074.htmlBroken LinkMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00077.htmlBroken LinkMailing ListThird Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1641487Issue TrackingPermissions RequiredVendor Advisory
- https://lists.debian.org/debian-lts-announce/2020/10/msg00020.htmlMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202010-02Third Party Advisory
- https://www.debian.org/security/2020/dsa-4770Third Party Advisory
FAQ
What is CVE-2020-15677?
CVE-2020-15677 is a vulnerability with a CVSS score of 6.1 (MEDIUM). By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redi...
How severe is CVE-2020-15677?
CVE-2020-15677 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-15677?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox, Mozilla Firefox Esr, Mozilla Thunderbird, Debian Debian Linux, Opensuse Leap.