First published: Tue May 05 2020(Updated: )
A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by selecting a different origin and removing focus from the input element. This vulnerability affects Firefox < 76.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <76 | 76 |
Mozilla Firefox | <76.0 | |
ubuntu/firefox | <76.0+ | 76.0+ |
ubuntu/firefox | <76.0+ | 76.0+ |
ubuntu/firefox | <76.0+ | 76.0+ |
ubuntu/firefox | <76.0+ | 76.0+ |
ubuntu/firefox | <76.0+ | 76.0+ |
ubuntu/firefox | <76.0+ | 76.0+ |
ubuntu/firefox | <76.0+ | 76.0+ |
ubuntu/firefox | <76.0+ | 76.0+ |
ubuntu/firefox | <76.0+ | 76.0+ |
ubuntu/firefox | <76.0+ | 76.0+ |
ubuntu/firefox | <76.0+ | 76.0+ |
ubuntu/firefox | <76.0 | 76.0 |
ubuntu/firefox | <76.0+ | 76.0+ |
debian/firefox | 130.0-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-12394 is classified as a moderate severity vulnerability due to the potential for local attackers to spoof the current location.
To mitigate CVE-2020-12394, upgrade your Firefox installation to version 76.0 or later.
CVE-2020-12394 affects all versions of Mozilla Firefox prior to version 76.
Users of Mozilla Firefox versions earlier than 76 are at risk from CVE-2020-12394.
CVE-2020-12394 is a logic flaw vulnerability in the location bar implementation of Firefox.