Mozilla: Content Security Policy violation report could have contained the destination of a redirect
Published Feb 26, 2021
4.3
MEDIUMCVSS 3.1
EPSS 1.21%
Description
As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s not possible, user agents need to strip the URL down to an origin to avoid unintentional leakage." Under certain types of redirects, Firefox incorrectly set the source file to be the destination of the redirects. This was fixed to be the redirect destination's origin. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
Affected products
-
- Version < 86StatusaffectedConstraints-
- Version
-
- Version < 78.8StatusaffectedConstraints-
- Version
-
- Version < 78.8StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mozilla | Firefox | n/a |
| ||||||
| Mozilla | Firefox ESR | n/a |
| ||||||
| Mozilla | Thunderbird | n/a |
|
Configuration 1
- < 86.0
- < 78.8
- < 78.8
Configuration 2
- 9.0
- 10.0
No data.
Red Hat Enterprise Linux 7
firefox-0:78.8.0-1.el7_9
Fixed · RHSA-2021:0656
Red Hat Enterprise Linux 7
thunderbird-0:78.8.0-1.el7_9
Fixed · RHSA-2021:0661
Red Hat Enterprise Linux 8
firefox-0:78.8.0-1.el8_3
Fixed · RHSA-2021:0655
Red Hat Enterprise Linux 8
thunderbird-0:78.8.0-1.el8_3
Fixed · RHSA-2021:0657
Red Hat Enterprise Linux 8.1 Extended Update Support
firefox-0:78.8.0-1.el8_1
Fixed · RHSA-2021:0659
Red Hat Enterprise Linux 8.1 Extended Update Support
thunderbird-0:78.8.0-1.el8_1
Fixed · RHSA-2021:0658
Red Hat Enterprise Linux 8.2 Extended Update Support
firefox-0:78.8.0-1.el8_2
Fixed · RHSA-2021:0660
Red Hat Enterprise Linux 8.2 Extended Update Support
thunderbird-0:78.8.0-1.el8_2
Fixed · RHSA-2021:0662
Red Hat Enterprise Linux 6
firefox
Out of support scope
Red Hat Enterprise Linux 6
thunderbird
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | firefox-0:78.8.0-1.el7_9 | Fixed | RHSA-2021:0656 |
| Red Hat Enterprise Linux 7 | thunderbird-0:78.8.0-1.el7_9 | Fixed | RHSA-2021:0661 |
| Red Hat Enterprise Linux 8 | firefox-0:78.8.0-1.el8_3 | Fixed | RHSA-2021:0655 |
| Red Hat Enterprise Linux 8 | thunderbird-0:78.8.0-1.el8_3 | Fixed | RHSA-2021:0657 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | firefox-0:78.8.0-1.el8_1 | Fixed | RHSA-2021:0659 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | thunderbird-0:78.8.0-1.el8_1 | Fixed | RHSA-2021:0658 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | firefox-0:78.8.0-1.el8_2 | Fixed | RHSA-2021:0660 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | thunderbird-0:78.8.0-1.el8_2 | Fixed | RHSA-2021:0662 |
| Red Hat Enterprise Linux 6 | firefox | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | thunderbird | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- https://access.redhat.com/security/cve/CVE-2021-23969 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1542194 x_refsource_MISCIssue TrackingPermissions RequiredVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1932109 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2021/03/msg00000.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-23969
- https://security.gentoo.org/glsa/202104-09 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.gentoo.org/glsa/202104-10 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2021-23969
- https://www.debian.org/security/2021/dsa-4866 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2021-08/#CVE-2021-23969
- https://www.mozilla.org/security/advisories/mfsa2021-07/ x_refsource_MISCRelease NotesVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2021-08/ x_refsource_MISCRelease NotesVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2021-09/ x_refsource_MISCRelease NotesVendor Advisory
Change history (0)
No recorded changes yet.