CVE-2020-12409: High severity firefox vulnerability
Published Jun 2, 2020
·Updated
Last updated 24 July 2024
Other sources
When using certain blank characters in a URL, they where incorrectly rendered as spaces instead of an encoded URL.
Affected Software
3 affected componentsFixes available
Mozilla Firefox<77
77
Mozilla Firefox<77.0
debian/firefox
137.0.2-1
Event History
Jun 2, 2020
CVE Published
12:00 AM
Jul 9, 2020
CVE Published
via MITRE·02:46 PM
Data Sourced
via MITRE·02:46 PM
DescriptionWeakness
Jan 11, 2024
Data Sourced
via Launchpad·11:38 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:21 AM
RemedyDescriptionSeverityAffected Software
Mar 27, 2025
Data Sourced
via Debian·03:31 AM
DescriptionAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is CVE-2020-12409?
CVE-2020-12409 is a vulnerability in Firefox < 77 that incorrectly renders certain blank characters in a URL as spaces instead of an encoded URL.
2
Who is affected by CVE-2020-12409?
Users of Firefox versions earlier than 77 are affected by CVE-2020-12409.
3
What is the severity of CVE-2020-12409?
CVE-2020-12409 is rated as high severity with a CVSS score of 8.8.
4
How does CVE-2020-12409 impact users?
CVE-2020-12409 may allow attackers to deceive users by rendering certain blank characters in a URL incorrectly.
5
How can I fix CVE-2020-12409?
To fix CVE-2020-12409, users should upgrade to Firefox version 77 or later.