First published: Tue Jul 28 2020(Updated: )
An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying on sandbox configurations that allowed popups and hosted arbitrary content. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <78.1 | 78.1 |
Mozilla Thunderbird | <78.1 | 78.1 |
Mozilla Firefox | <79 | 79 |
Mozilla Firefox | <79.0 | |
Mozilla Firefox ESR | <78.1 | |
Mozilla Thunderbird | <78.1 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =20.04 | |
debian/firefox | 132.0-1 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:115.16.0esr-1~deb11u1 1:115.12.0-1~deb12u1 1:115.16.0esr-1~deb12u1 1:128.3.2esr-1 1:128.4.0esr-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-15653 is a vulnerability discovered in Mozilla Firefox and Firefox ESR that allows the bypassing of the <iframe sandbox> with the allow-popups flag when using noopener links.
CVE-2020-15653 could lead to security issues for websites that rely on sandbox configurations allowing popups and hosting arbitrary content.
Mozilla Firefox ESR versions up to 78.1, Mozilla Firefox versions up to 79, and Mozilla Thunderbird versions up to 78.1 are affected by CVE-2020-15653.
CVE-2020-15653 has a severity level of medium.
To fix CVE-2020-15653, update your Mozilla Firefox ESR to version 78.1, Mozilla Firefox to version 79, or Mozilla Thunderbird to version 78.1.