If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
2020-01-08T20:15:12.873
2024-11-21T04:21:44.557
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:N
8.6
4.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mozilla | firefox | < 70.0 | Yes |
| Application | mozilla | firefox_esr | < 68.2 | Yes |
| Application | mozilla | thunderbird | < 68.2 | Yes |
| Operating System | canonical | ubuntu_linux | 16.04 | Yes |