CVE-2021-23963
Summary
| CVE | CVE-2021-23963 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-26 03:15:00 UTC |
| Updated | 2021-03-03 20:11:00 UTC |
| Description | When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user interface, leading to loss of control over the currently granted permission. This vulnerability affects Firefox < 85. |
Risk And Classification
Problem Types: CWE-281
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Access Denied | MISC | bugzilla.mozilla.org | Issue Tracking, Permissions Required, Vendor Advisory |
| Security Vulnerabilities fixed in Firefox 85 — Mozilla | MISC | www.mozilla.org | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.