SB2021022603 - Improperly implemented security check for standard in firefox-esr (Alpine package)



SB2021022603 - Improperly implemented security check for standard in firefox-esr (Alpine package)

Published: February 26, 2021

Security Bulletin ID SB2021022603
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improperly implemented security check for standard (CVE-ID: CVE-2021-23969)

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect implementation of W3C Content Security Policy. Under certain types of redirects Firefox incorrectly sets the source file to be the destination of the redirects. A remote attacker can gain knowledge of the destination URL.


Remediation

Install update from vendor's website.