CVE-2021-23956: Medium severity firefox vulnerability
Published Jan 26, 2021
·Updated
An ambiguous file picker design could have confused users who intended to select and upload a single file into uploading a whole directory. This was addressed by adding a new prompt.
Affected Software
2 affected componentsFixes available
Mozilla Firefox<85
85
Mozilla Firefox<85.0
Remediation
Patch Available
Event History
Jan 26, 2021
CVE Published
12:00 AM
Feb 26, 2021
CVE Published
via MITRE·02:09 AM
Data Sourced
via MITRE·02:09 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2021-23956?
CVE-2021-23956 has been rated as moderate severity due to the potential for user confusion and accidental directory uploads.
2
How do I fix CVE-2021-23956?
To fix CVE-2021-23956, update your Mozilla Firefox to version 85 or later.
3
What does CVE-2021-23956 affect?
CVE-2021-23956 affects Mozilla Firefox versions prior to 85.
4
What was the issue in CVE-2021-23956?
The issue in CVE-2021-23956 was an ambiguous file picker design that could mislead users into uploading entire directories instead of a single file.
5
What has been done to address CVE-2021-23956?
CVE-2021-23956 was addressed by introducing a new prompt to clarify the file selection process.