Information Exposure Affecting mozilla package, versions [,87.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.42% (75th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-MOZILLA-2378531
  • published26 Jan 2022
  • disclosed31 Mar 2021
  • creditUnknown

Introduced: 31 Mar 2021

CVE-2021-23985  (opens in a new tab)
CWE-668  (opens in a new tab)

How to fix?

Upgrade mozilla to version 87.0 or higher.

Overview

Affected versions of this package are vulnerable to Information Exposure. If an attacker is able to alter specific about:config values (for example malware running on the user's computer), the Devtools remote debugging feature could have been enabled in a way that was unnoticable to the user. This would have allowed a remote attacker (able to make a direct network connection to the victim) to monitor the user's browsing activity and (plaintext) network traffic. This was addressed by providing a visual cue when Devtools has an open network socket. This vulnerability affects Firefox < 87.

CVSS Scores

version 3.1