CVE-2020-15666 PUBLISHED

When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message. This level of information leakage is inconsistent with the standardized onerror/onsuccess disclosure and can lead to inferring login status to services or device discovery on a local network among other attacks. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

EPSS 0.37% · 58.8th percentile

Risk Scores

EPSS Score
0.37%
58.8th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSmozjs680, 68.6.0-1ubuntu1, 68.6.0-1
Ubuntu:18.04:LTSfirefox56.0+build6-0ubuntu1, 60.0+build2-0ubuntu1, 59.0.2+build1-0ubuntu1
Ubuntu:18.04:LTSmozjs5252.9.1-0ubuntu0.18.04.1, 52.8.1-0ubuntu0.18.04.1, 52.3.1-7fakesync1
Ubuntu:20.04:LTSmozjs5252.9.1-1ubuntu3, 0, 52.9.1-1build1
Ubuntu:20.04:LTSfirefox79.0+build1-0ubuntu0.20.04.1, 78.0.2+build2-0ubuntu0.20.04.1, 78.0.1+build1-0ubuntu0.20.04.1
Ubuntu:16.04:LTSfirefox66.0.5+build1-0ubuntu0.16.04.1, 66.0.4+build3-0ubuntu0.16.04.1, 66.0.3+build1-0ubuntu0.16.04.1
Ubuntu:18.04:LTSmozjs3838.8.0~repack1-0ubuntu4, 38.8.0~repack1-0ubuntu3, 38.8.0~repack1-0ubuntu1

Timeline

References

Open in Interactive Console →