CVE-2020-6823
24.04.2020, 16:15
A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, and through the Promise returned, obtain the Auth code and gain access to the user's account at the service provider. This vulnerability affects Firefox < 75.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 < 75.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||||||||||||||||
mozjs38 |
| ||||||||||||||||||||||||||
mozjs52 |
| ||||||||||||||||||||||||||
mozjs60 |
| ||||||||||||||||||||||||||
mozjs68 |
|
Common Weakness Enumeration