CVE-2020-15655: Medium severity Mozilla Firefox vulnerability
A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-origin information. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
Other sources
Mozilla Developer Rob Wu discovered that a redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-origin information.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-15655.
Who discovered this vulnerability?
Mozilla Developer Rob Wu discovered this vulnerability.
What is the impact of this vulnerability?
This vulnerability could bypass existing CORS checks, leading to potential disclosure of cross-origin information.
Which software products are affected by this vulnerability?
Firefox ESR 78.1, Thunderbird 78.1, and Firefox 79 are affected by this vulnerability.
What is the severity of CVE-2020-15655?
The severity of CVE-2020-15655 is high (7.0).
How can I fix this vulnerability?
Update Firefox ESR to version 78.1, Thunderbird to version 78.1, or Firefox to version 79 to fix this vulnerability.