CVE-2020-15653

MEDIUM

Firefox ESR < 78.1 & Firefox < 79 & Thunderbird < 78.1 - CSRF

Title source: llm
STIX 2.1

Description

An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying on sandbox configurations that allowed popups and hosted arbitrary content. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

References (6)

Core 6
Core References
Issue Tracking, Permissions Required, Vendor Advisory x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=1521542
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00025.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4443-1/

Scores

CVSS v3 6.5
EPSS 0.0028
EPSS Percentile 51.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

Status published
Products (6)
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 20.04
mozilla/firefox < 79.0
mozilla/firefox_esr < 78.1
mozilla/thunderbird < 78.1
Published Aug 10, 2020
Tracked Since Feb 18, 2026