Vulnerability Name: | CVE-2020-15647 (CCN-186890) | ||||||||||||
Assigned: | 2020-07-20 | ||||||||||||
Published: | 2020-07-20 | ||||||||||||
Updated: | 2020-08-12 | ||||||||||||
Summary: | A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. This vulnerability affects Firefox for < Android. | ||||||||||||
CVSS v3 Severity: | 7.4 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N) 6.4 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-15647 Source: MISC Type: Issue Tracking, Vendor Advisory https://bugzilla.mozilla.org/show_bug.cgi?id=1647078 Source: XF Type: UNKNOWN mozilla-cve202015647-info-disc(186890) Source: CCN Type: Firefox Web site Firefox Source: CCN Type: Mozilla Foundation Security Advisory 2020-27 Security Vulnerabilities fixed in Firefox for Android 68.10.1 Source: MISC Type: Vendor Advisory https://www.mozilla.org/security/advisories/mfsa2020-27/ | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |