Related Vulnerabilities: CVE-2021-23971  

A security issue was found in Firefox before version 86.0. When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redirect's Referrer-Policy. This would have potentially resulted in more information than intended by the original origin being provided to the destination of the redirect.

Severity Medium

Remote Yes

Type Information disclosure

Description

A security issue was found in Firefox before version 86.0. When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redirect's Referrer-Policy. This would have potentially resulted in more information than intended by the original origin being provided to the destination of the redirect.

AVG-1599 firefox 85.0.2-1 86.0-1 High Fixed

https://www.mozilla.org/en-US/security/advisories/mfsa2021-07/#CVE-2021-23971
https://bugzilla.mozilla.org/show_bug.cgi?id=1678545