CVE-2021-29974 PUBLISHED

When network partitioning was enabled, e.g. as a result of Enhanced Tracking Protection settings, a TLS error page would allow the user to override an error on a domain which had specified HTTP Strict Transport Security (which implies that the error should not be override-able.) This issue did not affect the network connections, and they were correctly upgraded to HTTPS automatically. This vulnerability affects Firefox < 90.

EPSS 0.39% · 59.9th percentile

Risk Scores

EPSS Score
0.39%
59.9th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSfirefox*, *, *
Ubuntu:18.04:LTSfirefox76.0+build2-0ubuntu0.18.04.1, 76.0.1+build1-0ubuntu0.18.04.1, 77.0.1+build1-0ubuntu0.18.04.1
Ubuntu:22.04:LTSmozjs780, 78.13.0-1, 78.15.0-2
Ubuntu:20.04:LTSmozjs6868.5.0-2~fakesync, 68.6.0-1, 68.6.0-1ubuntu1
Ubuntu:18.04:LTSmozjs5252.9.1-0ubuntu0.18.04.1, 52.3.1-7fakesync1, 52.3.1-0ubuntu3
Ubuntu:20.04:LTSmozjs5252.9.1-1ubuntu3, 0, 52.9.1-1build1
Ubuntu:18.04:LTSmozjs38*, 0, 38.8.0~repack1-0ubuntu1

Timeline

References

Open in Interactive Console →