First published: Tue Jan 26 2021(Updated: )
An ambiguous file picker design could have confused users who intended to select and upload a single file into uploading a whole directory. This was addressed by adding a new prompt.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <85 | 85 |
Firefox | <85.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-23956 has been rated as moderate severity due to the potential for user confusion and accidental directory uploads.
To fix CVE-2021-23956, update your Mozilla Firefox to version 85 or later.
CVE-2021-23956 affects Mozilla Firefox versions prior to 85.
The issue in CVE-2021-23956 was an ambiguous file picker design that could mislead users into uploading entire directories instead of a single file.
CVE-2021-23956 was addressed by introducing a new prompt to clarify the file selection process.