First published: Fri Feb 28 2020(Updated: )
A reflected XSS vulnerability exists within the gateway, allowing an attacker to craft a specialized URL which could steal the user's authentication token. When combined with CVE-2020-6803, an attacker could fully compromise the system.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Webthings Gateway | >=0.3.0<0.12.0 |
https://github.com/mozilla-iot/gateway/pull/2446
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.