First published: Fri Feb 28 2020(Updated: )
An open redirect is present on the gateway's login page, which could cause a user to be redirected to a malicious site after logging in.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla WebThings Gateway | <2020-02-26 |
https://github.com/mozilla-iot/gateway/pull/2446
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6803 is classified as a medium severity vulnerability due to its potential for user redirection to malicious sites.
To fix CVE-2020-6803, update the Mozilla Webthings Gateway to a version released after February 26, 2020.
CVE-2020-6803 may lead to phishing attacks, as users can be redirected to malicious sites after logging in.
CVE-2020-6803 affects all versions of Mozilla Webthings Gateway up to and including February 26, 2020.
Yes, CVE-2020-6803 can be exploited remotely, allowing attackers to redirect users to unintended websites.