CVE-2020-12415: Medium severity firefox vulnerability
Last updated 24 July 2024
Other sources
When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory. This vulnerability affects Firefox < 78.
— Launchpad
When %2F was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory.
When %2F was present in a manifest URL, Thunderbird's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-12415.
What is the severity of CVE-2020-12415?
The severity of CVE-2020-12415 is high.
Which software products are affected by CVE-2020-12415?
Mozilla Firefox and Mozilla Thunderbird versions up to exclusive 78 are affected by CVE-2020-12415.
What is the impact of CVE-2020-12415?
CVE-2020-12415 could cause Thunderbird's AppCache behavior to become confused and allow a manifest to be served from a subdirectory, potentially leading to the appcache being used to service requests for the top level directory.
How can I fix CVE-2020-12415?
Mozilla has released a fix for CVE-2020-12415 in Firefox version 78 and Thunderbird version 78. Users are advised to update to the latest available versions to mitigate the vulnerability.