Skip to content
This repository has been archived by the owner on Jul 5, 2021. It is now read-only.

Firefox Lite history.replaceState same-origin check failure

High
st3fan published GHSA-vm4v-cxqj-jjgm Jan 29, 2021

Package

No package listed

Affected versions

< 2.6.0

Patched versions

2.6.0

Description

Impact

Users for Firefox Lite can be tricked into loading a web page that presents itself as a different page by modifying (spoofing) the URL shown in the location bar.

Patches

This issue has been patched in Firefox Lite 2.6.0, which is available through the Google Play Store (not available in all regions) or for direct download through the 2.6.0 Release page.

Workarounds

No workaround is available. It is recommended to upgrade to Firefox Lite 2.6.0.

References

This issue is documented and discussed in Bugzilla #1684986.

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2021-23966

Weaknesses

No CWEs

Credits