6.5
CVSSv3

CVE-2020-15655

Published: 10/08/2020 Updated: 03/05/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-origin information. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla thunderbird

mozilla firefox esr

mozilla firefox

opensuse leap 15.2

canonical ubuntu linux 18.04

canonical ubuntu linux 20.04

canonical ubuntu linux 16.04

Vendor Advisories

Severity Unknown Remote Unknown Type Unknown Description AVG-1214 thunderbird 68110-1 High Vulnerable AVG-1213 firefox 7802-1 790-1 High Fixed ...
Mozilla Foundation Security Advisory 2020-30 Security Vulnerabilities fixed in Firefox 79 Announced July 28, 2020 Impact high Products Firefox Fixed in Firefox 79 ...
Mozilla Foundation Security Advisory 2020-33 Security Vulnerabilities fixed in Thunderbird 781 Announced July 28, 2020 Impact high Products Thunderbird Fixed in Thunderbird 781 ...
Mozilla Foundation Security Advisory 2020-32 Security Vulnerabilities fixed in Firefox ESR 781 Announced July 28, 2020 Impact high Products Firefox ESR Fixed in Firefox ESR 781 ...