Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
CVE-2020-15677
CVE information
Published
Last Modified
CVSSv2.0 Severity
CVSSv3.1 Severity
Impact Analysis
Description
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3..
CVSSv2.0 Score
- Severity
- Medium
- Base Score
- 5.8/10
- Exploit Score
- 8.6/10
- Access Vector
- Network
- Access Complexity
- Medium
- Authentication Required
- None
- Impact Score
- 4.9/10
- Confidentiality Impact
- Partial
- Availability Impact
- None
- Integrity Impact
- Partial
CVSSv3.1 Score
- Severity
- Medium
- Base Score
- 6.1/10
- Exploit Score
- 2.8/10
- Access Vector
- Network
- Access Complexity
- Low
- Privileges Required
- None
- Impact Score
- 2.7/10
- Confidentiality Impact
- Low
- Availability Impact
- None
- Integrity Impact
- Low
- Scope
- Changed
- User Interaction
- Required
Products Affected
CPE | Affected | Vulnerable | Excluding | Edit |
---|---|---|---|---|
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* |
Yes
|
- | 78.3 | |
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
Yes
|
- | 78.3 | |
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
Yes
|
- | 81.0 | |
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:* |
Yes
|
- | - |
References
- https://www.mozilla.org/security/advisories/mfsa2020-42/
- https://www.mozilla.org/security/advisories/mfsa2020-43/
- https://bugzilla.mozilla.org/show_bug.cgi?id=1641487
- https://www.mozilla.org/security/advisories/mfsa2020-44/
- https://www.debian.org/security/2020/dsa-4770
- https://lists.debian.org/debian-lts-announce/2020/10/msg00020.html
- https://security.gentoo.org/glsa/202010-02
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00077.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00074.html