First published: Tue Jul 20 2021(Updated: )
Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically prepared request, lead to remote code execution.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Geckodriver | <0.27.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15660 has been classified as a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2020-15660, users should update Geckodriver to version 0.27.0 or later.
CVE-2020-15660 is a Cross-Site Request Forgery (CSRF) vulnerability related to missing checks on Content-Type headers.
Versions of Geckodriver prior to 0.27.0 are affected by CVE-2020-15660.
Yes, CVE-2020-15660 can lead to remote code execution if exploited with a specifically prepared request.