CVE-2020-6798 log

Source
Severity Medium
Remote Yes
Type Cross-site scripting
Description
An incorrect parsing of template could result in Javascript injection in Firefox before 73.0 and Thunderbird before 68.5. If a <template> tag was used in a <select%gt; tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result.
In general, this flaw cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but is potentially a risk in browser or browser-like contexts.
Group Package Affected Fixed Severity Status Ticket
AVG-1099 thunderbird 68.4.2-1 68.5.0-1 Critical Fixed
AVG-1096 firefox 72.0.2-1 73.0-1 Critical Fixed
Date Advisory Group Package Severity Description
13 Feb 2020 ASA-202002-9 AVG-1099 thunderbird Critical multiple issues
11 Feb 2020 ASA-202002-5 AVG-1096 firefox Critical multiple issues
References
https://www.mozilla.org/en-US/security/advisories/mfsa2020-05/#CVE-2020-6798
https://www.mozilla.org/en-US/security/advisories/mfsa2020-07/#CVE-2020-6798
https://bugzilla.mozilla.org/show_bug.cgi?id=1602944