CVE-2021-43540: Medium severity firefox vulnerability
Published Dec 7, 2021
·Updated
WebExtensions with the correct permissions were able to create and install ServiceWorkers for third-party websites that would not have been uninstalled with the extension.
Affected Software
2 affected componentsFixes available
Mozilla Firefox<95
95
Mozilla Firefox<95.0
Event History
Dec 7, 2021
CVE Published
12:00 AM
Dec 8, 2021
CVE Published
via MITRE·09:20 PM
Data Sourced
via MITRE·09:20 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2021-43540?
CVE-2021-43540 is classified as a moderate severity vulnerability that allows WebExtensions to improperly manage ServiceWorkers.
2
How do I fix CVE-2021-43540?
To mitigate CVE-2021-43540, users should update their Mozilla Firefox browser to version 96 or higher.
3
What are the potential impacts of CVE-2021-43540?
CVE-2021-43540 could allow third-party websites to retain ServiceWorkers even after the uninstallation of the associated WebExtension.
4
Which versions of Firefox are affected by CVE-2021-43540?
CVE-2021-43540 affects Mozilla Firefox versions prior to 96.
5
Who is responsible for addressing CVE-2021-43540?
Mozilla is responsible for addressing and patching CVE-2021-43540 in its Firefox browser.