CVE-2020-26976: Medium severity thunderbird vulnerability
When a HTTPS page was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing.
Other sources
When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2020-26976?
CVE-2020-26976 is considered a moderate severity vulnerability.
How do I fix CVE-2020-26976?
To fix CVE-2020-26976, you should update your software to the latest version as specified in the vulnerability details.
Which versions are affected by CVE-2020-26976?
CVE-2020-26976 affects Mozilla Firefox versions prior to 84, as well as Thunderbird and Firefox ESR versions before 78.7.
What kind of vulnerability is CVE-2020-26976?
CVE-2020-26976 is a security vulnerability that relates to the improper handling of HTTPS pages embedded in HTTP contexts.
Is CVE-2020-26976 exploitable?
Yes, CVE-2020-26976 can potentially be exploited by attackers to intercept secure communications when HTTPS content is improperly framed.