First published: Fri Feb 28 2020(Updated: )
A reflected XSS vulnerability exists within the gateway, allowing an attacker to craft a specialized URL which could steal the user's authentication token. When combined with CVE-2020-6803, an attacker could fully compromise the system.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla WebThings Gateway | >=0.3.0<0.12.0 |
https://github.com/mozilla-iot/gateway/pull/2446
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6804 has a medium severity rating due to its potential for exploiting user authentication tokens.
To fix CVE-2020-6804, update the Mozilla WebThings Gateway to a version later than 0.12.0.
CVE-2020-6804 is caused by a reflected XSS vulnerability that allows attackers to craft malicious URLs.
CVE-2020-6804 is exploitable on versions between 0.3.0 and 0.12.0 of Mozilla WebThings Gateway.
Yes, CVE-2020-6804 can allow attackers to steal user authentication tokens, leading to potential data theft.