UBUNTU-CVE-2021-23968
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-23968
UBUNTU-CVE-2021-23968
Summary:
Details: If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
References: https://ubuntu.com/security/CVE-2021-23968, https://www.mozilla.org/en-US/security/advisories/mfsa2021-07/#CVE-2021-23968, https://www.mozilla.org/en-US/security/advisories/mfsa2021-08/#CVE-2021-23968, https://www.mozilla.org/en-US/security/advisories/mfsa2021-09/#CVE-2021-23968, https://bugzilla.mozilla.org/show_bug.cgi?id=1687342, https://www.mozilla.org/security/advisories/mfsa2021-07/, https://www.mozilla.org/security/advisories/mfsa2021-08/, https://www.mozilla.org/security/advisories/mfsa2021-09/, https://ubuntu.com/security/notices/USN-4756-1, https://ubuntu.com/security/notices/USN-4936-1, https://www.cve.org/CVERecord?id=CVE-2021-23968
Affected packages
Package
Name: firefox
Purl: pkg:deb/ubuntu/[email protected]+build3-0ubuntu0.16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
