First published: Tue Oct 22 2019(Updated: )
By navigating a tab using the history API, an attacker could cause the address bar to display the incorrect domain (with the https:// scheme, a blocked port number such as '1', and without a lock icon) while controlling the page contents.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <70 | 70 |
<70 | 70 | |
Mozilla Firefox | <70.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-12412 is a vulnerability in Mozilla Firefox that allows an attacker to manipulate the address bar to display an incorrect domain.
CVE-2020-12412 works by using the history API to navigate a tab and control the page contents, causing the address bar to display the incorrect domain.
CVE-2020-12412 has a severity level of medium.
Mozilla Firefox version 70 (up to exclusive) is affected by CVE-2020-12412.
To fix CVE-2020-12412, update Mozilla Firefox to a version higher than 70.