First published: Thu May 06 2021(Updated: )
Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata service.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Hubs Cloud mozillareality/reticulum//20210428201255 | <1.0.1 | 1.0.1 |
<1.0.1 | 1.0.1 | |
Mozilla Hubs Cloud Reticulum | <1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29954 is rated with a severity level that indicates risk due to exposure of internal URLs.
To fix CVE-2021-29954, you should update Hubs Cloud's Reticulum software to version 1.0.1 or later.
CVE-2021-29954 affects the Mozilla Hubs Cloud Reticulum software versions prior to 1.0.1.
The impact of CVE-2021-29954 allows unauthorized access to internal URLs, potentially exposing sensitive information.
CVE-2021-29954 was disclosed as part of the Mozilla security advisories in 2021.