Session Fixation Affecting firefox package, versions <75.0-1


0.0
low

Snyk CVSS

    Attack Complexity Low
    User Interaction Required

    Threat Intelligence

    EPSS 0.04% (12th percentile)
Expand this section
NVD
2.8 low
Expand this section
Red Hat
2.8 low

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-DEBIANUNSTABLE-FIREFOX-564622
  • published 7 Apr 2020
  • disclosed 24 Apr 2020

How to fix?

Upgrade Debian:unstable firefox to version 75.0-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream firefox package and not the firefox package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open. Subsequently, if the user had opened a new Private Browsing Window, revisited the same site, and generated a new password - the generated passwords would have been identical, rather than independent. This vulnerability affects Firefox < 75.