Back

MEDIUM

Mozilla: Potential leak of redirect targets when loading scripts in a worker

Published Aug 10, 2020

Description

By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Aug 10, 2020
Updated Aug 4, 2024
Reserved Jul 10, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jul 28, 2020