In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Improper Input Validation vulnerabilities in an interactive lesson.
Start learningUpgrade RHEL:8
firefox
to version 0:68.6.0-1.el8_1 or higher.
This issue was patched in RHSA-2020:0820
.
Note: Versions mentioned in the description apply only to the upstream firefox
package and not the firefox
package as distributed by RHEL
.
See How to fix?
for RHEL:8
relevant fixed versions and status.
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.