CVE-2020-26962 PUBLISHED

Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This vulnerability affects Firefox < 83.

EPSS 0.22% · 44.4th percentile

Risk Scores

EPSS Score
0.22%
44.4th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSmozjs680, 68.6.0-1ubuntu1, 68.6.0-1
Ubuntu:18.04:LTSfirefox80.0.1+build1-0ubuntu0.18.04.1, 0, 56.0+build6-0ubuntu1
Ubuntu:20.04:LTSmozjs5252.9.1-1build1, 52.9.1-1ubuntu3, 0
Ubuntu:18.04:LTSmozjs5252.8.1-0ubuntu0.18.04.1, 52.3.1-0ubuntu3, 52.3.1-7fakesync1
Ubuntu:16.04:LTSfirefox68.0.1+build1-0ubuntu0.16.04.1, 68.0.2+build1-0ubuntu0.16.04.1, 69.0+build2-0ubuntu0.16.04.4
Ubuntu:18.04:LTSmozjs380, 38.8.0~repack1-0ubuntu1, 38.8.0~repack1-0ubuntu3
Ubuntu:20.04:LTSfirefox81.0+build2-0ubuntu0.20.04.1, 80.0.1+build1-0ubuntu0.20.04.1, 80.0+build2-0ubuntu0.20.04.1

Timeline

References

Open in Interactive Console →