CVE-2020-15660
20.07.2021, 12:15
Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically prepared request, lead to remote code execution.
Vendor | Product | Version |
---|---|---|
mozilla | geckodriver | 𝑥 < 0.27.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||||
mozjs38 |
| ||||||||||||||
mozjs52 |
| ||||||||||||||
mozjs68 |
| ||||||||||||||
mozjs78 |
| ||||||||||||||
thunderbird |
|
Common Weakness Enumeration