CVE-2020-26955: Medium severity firefox vulnerability
When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes. Note: This issue only affected Firefox for Android. Other operating systems are unaffected.. This vulnerability affects Firefox < 83.
Other sources
When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes.Note: This issue only affected Firefox for Android. Other operating systems are unaffected.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-26955?
CVE-2020-26955 is a vulnerability in Firefox for Android that allows a re-sending of cookies during subsequent file download operations on the same domain, regardless of browsing mode.
How does CVE-2020-26955 affect Firefox for Android?
CVE-2020-26955 affects Firefox for Android by allowing cookies to be re-sent during subsequent file downloads on the same domain.
What is the severity of CVE-2020-26955?
The severity of CVE-2020-26955 is medium with a CVSS score of 6.5.
How can I fix the CVE-2020-26955 vulnerability in Firefox for Android?
To fix the CVE-2020-26955 vulnerability in Firefox for Android, update to version 83 or higher.
Where can I find more information about CVE-2020-26955?
For more information about CVE-2020-26955, you can refer to the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1663261), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2020-50/)