CVE-2021-29958: Medium severity firefox vulnerability
Published Jun 1, 2021
·Updated
When a download was initiated, the client did not check whether it was in normal or private browsing mode, which led to private mode cookies being shared in normal browsing mode.
Affected Software
3 affected components
Mozilla Firefox Iphone Os<34.0
All of the following
Mozilla Firefox=34
Apple iOS
Event History
Jun 1, 2021
CVE Published
12:00 AM
Jun 24, 2021
CVE Published
via MITRE·01:16 PM
Data Sourced
via MITRE·01:16 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-29958?
CVE-2021-29958 is classified as a moderate severity vulnerability due to its potential to expose private browsing data.
2
How do I fix CVE-2021-29958?
To fix CVE-2021-29958, update your Mozilla Firefox browser to the latest version that addresses this security issue.
3
What causes CVE-2021-29958?
CVE-2021-29958 is caused by the client's failure to properly segregate private browsing mode cookies when a download is initiated.
4
What are the potential impacts of CVE-2021-29958?
The potential impacts of CVE-2021-29958 include unauthorized access to private mode cookies in normal browsing sessions.
5
Which versions of Firefox are affected by CVE-2021-29958?
CVE-2021-29958 affects Firefox versions up to but not including 34.0 on iOS.