QID 630669

Date Published: 2021-04-07

QID 630669: Mozilla Firefox for Android and iOS Multiple Vulnerabilities (MFSA2021-07)

Firefox is a free and open-source web browser developed for Windows, OS X, and Linux, with a mobile version for Android.

CVE-2021-23969: Content Security Policy violation report could have contained the destination of a redirect.
CVE-2021-23970: Multithreaded WASM triggered assertions validating separation of script domains.
CVE-2021-23968: Content Security Policy violation report could have contained the destination of a redirect.
CVE-2021-23974: noscript elements could have led to an HTML Sanitizer bypass.
CVE-2021-23971: A website's Referrer-Policy could have been be overridden, potentially resulting in the full URL being sent as a Referrer.
CVE-2021-23972: HTTP Auth phishing warning was omitted when a redirect is cached.
CVE-2021-23975: about:memory Measure function caused an incorrect pointer operation.
CVE-2021-23973: MediaError message property could have leaked information about cross-origin resources.
CVE-2021-23979: Memory safety bugs fixed in Firefox 86.

Affected Products:
Prior to Firefox 86

On successful exploitation it could allow to compromise integrity, availability and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Vendor has released fix to address these vulnerabilities. Refer to MFSA 2021-07
    Software Advisories
    Advisory ID Software Component Link
    mfsa2021-07 Android URL Logo www.mozilla.org/en-US/security/advisories/mfsa2021-07/
    mfsa2021-07 iOS URL Logo www.mozilla.org/en-US/security/advisories/mfsa2021-07/