CVE-2020-15653
Summary
| CVE | CVE-2020-15653 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-10 18:15:00 UTC |
| Updated | 2023-02-02 22:19:00 UTC |
| Description | An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying on sandbox configurations that allowed popups and hosted arbitrary content. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 20.04 | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Firefox Esr | All | All | All | All |
| Application | Mozilla | Firefox Esr | All | All | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Vulnerabilities fixed in Firefox 79 — Mozilla | MISC | www.mozilla.org | Vendor Advisory |
| [security-announce] openSUSE-SU-2020:1189-1: important: Security update | SUSE | lists.opensuse.org | Third Party Advisory |
| Security Vulnerabilities fixed in Firefox ESR 78.1 — Mozilla | MISC | www.mozilla.org | Vendor Advisory |
| Security Vulnerabilities fixed in Thunderbird 78.1 — Mozilla | MISC | www.mozilla.org | Vendor Advisory |
| USN-4443-1: Firefox vulnerabilities | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | |
| Access Denied | MISC | bugzilla.mozilla.org | Issue Tracking, Permissions Required, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.