CVE-2020-12394: Low severity firefox vulnerability
Published May 5, 2020
·Updated
A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by selecting a different origin and removing focus from the input element. This vulnerability affects Firefox < 76.
Affected Software
16 affected componentsFixes available
ubuntu/firefox<76.0+
76.0+
ubuntu/firefox<76.0+
76.0+
ubuntu/firefox<76.0+
76.0+
ubuntu/firefox<76.0+
76.0+
ubuntu/firefox<76.0+
76.0+
ubuntu/firefox<76.0+
76.0+
ubuntu/firefox<76.0+
76.0+
ubuntu/firefox<76.0+
76.0+
ubuntu/firefox<76.0+
76.0+
ubuntu/firefox<76.0+
76.0+
ubuntu/firefox<76.0+
76.0+
ubuntu/firefox<76.0
76.0
ubuntu/firefox<76.0+
76.0+
debian/firefox
130.0-2
Mozilla Firefox<76
76
Mozilla Firefox<76.0
Event History
May 5, 2020
CVE Published
12:00 AM
May 26, 2020
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Jan 11, 2024
Data Sourced
via Launchpad·11:37 PM
Description
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2020-12394?
CVE-2020-12394 is classified as a moderate severity vulnerability due to the potential for local attackers to spoof the current location.
2
How do I fix CVE-2020-12394?
To mitigate CVE-2020-12394, upgrade your Firefox installation to version 76.0 or later.
3
What versions of Firefox are affected by CVE-2020-12394?
CVE-2020-12394 affects all versions of Mozilla Firefox prior to version 76.
4
Who is impacted by CVE-2020-12394?
Users of Mozilla Firefox versions earlier than 76 are at risk from CVE-2020-12394.
5
What type of vulnerability is CVE-2020-12394?
CVE-2020-12394 is a logic flaw vulnerability in the location bar implementation of Firefox.