First published: Tue Nov 17 2020(Updated: )
When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <83 | 83 |
<83 | 83 | |
Mozilla Firefox | <83.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-26955 is a vulnerability in Firefox for Android that allows a re-sending of cookies during subsequent file download operations on the same domain, regardless of browsing mode.
CVE-2020-26955 affects Firefox for Android by allowing cookies to be re-sent during subsequent file downloads on the same domain.
The severity of CVE-2020-26955 is medium with a CVSS score of 6.5.
To fix the CVE-2020-26955 vulnerability in Firefox for Android, update to version 83 or higher.
For more information about CVE-2020-26955, you can refer to the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1663261), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2020-50/)