CVE-2021-38508 - log back

CVE-2021-38508 edited at 03 Nov 2021 16:45:30
Description
- By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could have obscured the prompt, resulting in the user potentially being tricked into granting the permission.
+ A security issue has been found in Firefox before version 94 and Thunderbird before version 91.3. By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could have obscured the prompt, resulting in the user potentially being tricked into granting the permission.
References
https://www.mozilla.org/security/advisories/mfsa2021-48/
+ https://www.mozilla.org/security/advisories/mfsa2021-50/
https://bugzilla.mozilla.org/show_bug.cgi?id=1366818
CVE-2021-38508 created at 02 Nov 2021 13:16:46
Severity
+ Medium
Remote
+ Remote
Type
+ Content spoofing
Description
+ By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could have obscured the prompt, resulting in the user potentially being tricked into granting the permission.
References
+ https://www.mozilla.org/security/advisories/mfsa2021-48/
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1366818
Notes