CVE-2020-15671

When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary. This vulnerability affects Firefox for Android < 80.
References
Link Resource
https://bugzilla.mozilla.org/show_bug.cgi?id=1653862 Issue Tracking Permissions Required Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2020-39/ Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:android:*:*

History

No history.

Information

Published : 2020-10-01 19:15

Updated : 2024-02-04 21:23


NVD link : CVE-2020-15671

Mitre link : CVE-2020-15671

CVE.ORG link : CVE-2020-15671


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')