CVE-2020-12392: Path Traversal
Last updated 24 July 2024
Other sources
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in the disclosure of local files.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2020-12392?
CVE-2020-12392 has been classified as a moderate severity vulnerability.
How do I fix CVE-2020-12392?
To fix CVE-2020-12392, users should update to the latest version of Firefox or Thunderbird that exceeds the affected versions listed.
What products are affected by CVE-2020-12392?
CVE-2020-12392 affects Mozilla Firefox ESR, Mozilla Thunderbird, and certain versions of Firefox.
What type of vulnerability is CVE-2020-12392?
CVE-2020-12392 is a security flaw related to improper handling of HTTP POST data in the 'Copy as cURL' feature of browser devtools.
What could be the impact of exploiting CVE-2020-12392?
Exploiting CVE-2020-12392 could potentially lead to the disclosure of sensitive information if a user inadvertently runs a pasted curl command.