CVE-2020-6823: Critical severity firefox vulnerability
A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirecturi, and through the Promise returned, obtain the Auth code and gain access to the user's account at the service provider. This vulnerability affects Firefox < 75.
Other sources
A malicious extension could have called browser.identity.launchWebAuthFlow, controlling the redirecturi, and through the Promise returned, obtain the Auth code and gain access to the user's account at the service provider.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-6823.
What is the severity level of CVE-2020-6823?
The severity level of CVE-2020-6823 is critical with a score of 9.8.
Which software is affected by CVE-2020-6823?
The software affected by CVE-2020-6823 is Mozilla Firefox versions before 75.
How can this vulnerability be exploited?
A malicious extension could call browser.identity.launchWebAuthFlow, controlling the redirect_uri to obtain the Auth code and gain access to the user's account at the service provider.
Is there a fix available for CVE-2020-6823?
Yes, updating to Mozilla Firefox version 75 or above will fix the vulnerability.