CVE-2020-12394 - log back

CVE-2020-12394 edited at 06 May 2020 09:37:05
Description
- A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by selecting a different origin and removing focus from the input element.
+ A logic flaw has been found in the location bar implementation of Firefox before 76.0, and could have allowed a local attacker to spoof the current location by selecting a different origin and removing focus from the input element.
References
+ https://www.mozilla.org/en-US/security/advisories/mfsa2020-16/#CVE-2020-12394
https://bugzilla.mozilla.org/show_bug.cgi?id=1628288
CVE-2020-12394 edited at 05 May 2020 17:19:45
Severity
- Unknown
+ Low
Remote
- Unknown
+ Remote
Type
- Unknown
+ Content spoofing
Description
+ A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by selecting a different origin and removing focus from the input element.
References
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1628288
Notes
CVE-2020-12394 created at 05 May 2020 17:16:55