First published: Tue Jul 13 2021(Updated: )
When network partitioning was enabled, e.g. as a result of Enhanced Tracking Protection settings, a TLS error page would allow the user to override an error on a domain which had specified HTTP Strict Transport Security (which implies that the error should not be override-able.) This issue did not affect the network connections, and they were correctly upgraded to HTTPS automatically.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <90 | 90 |
<90 | 90 | |
Mozilla Firefox | <90.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2021-29974 is considered moderate due to its implications on HTTP Strict Transport Security.
To fix CVE-2021-29974, users should update Firefox to version 90.0 or later.
CVE-2021-29974 affects all versions of Firefox prior to 90.0.
CVE-2021-29974 allows users to override a TLS error page on domains with HTTP Strict Transport Security enabled.
Currently, the only reliable workaround for CVE-2021-29974 is to disable Enhanced Tracking Protection settings.