CVE-2020-15648: Medium severity thunderbird vulnerability
Published Jul 8, 2020
·Updated
Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header.
Affected Software
4 affected componentsFixes available
Mozilla Thunderbird<78
78
Mozilla Firefox<78.0.2
Mozilla Thunderbird<78.0
Mozilla Firefox<78.0.2
78.0.2
Event History
Jul 8, 2020
CVE Published
12:00 AM
Aug 10, 2020
CVE Published
via MITRE·05:43 PM
Data Sourced
via MITRE·05:43 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is CVE-2020-15648?
CVE-2020-15648 is a vulnerability where it was possible to frame other websites using object or embed tags, even if they disallowed framing using the X-Frame-Options header.
2
How does CVE-2020-15648 affect Mozilla Firefox?
CVE-2020-15648 affects Mozilla Firefox versions up to and excluding 78.0.2.
3
How does CVE-2020-15648 affect Mozilla Thunderbird?
CVE-2020-15648 affects Mozilla Thunderbird versions up to and excluding 78.
4
What is the severity of CVE-2020-15648?
The severity of CVE-2020-15648 is medium with a CVSS score of 6.5.
5
How can I fix CVE-2020-15648?
To fix CVE-2020-15648, update Mozilla Firefox to version 78.0.2 or newer, or update Mozilla Thunderbird to version 78 or newer.