When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message. This level of information leakage is inc…
Medium CVSS 6.5
Summary
When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message. This level of information leakage is inconsistent with the standardized onerror/onsuccess disclosure and can lead to inferring login status to services or device discovery on a local network among other attacks. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://bugzilla.mozilla.org/show_bug.cgi?id=1450853 Exploit
- https://www.mozilla.org/security/advisories/mfsa2020-36/ Release Notes
- https://www.mozilla.org/security/advisories/mfsa2020-39/ Release Notes
- https://bugzilla.mozilla.org/show_bug.cgi?id=1450853 Exploit
- https://www.mozilla.org/security/advisories/mfsa2020-36/ Release Notes
- https://www.mozilla.org/security/advisories/mfsa2020-39/ Release Notes
Timeline
- nvd_ingest NVD