When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not triggered for view-source URLs. While web content cannot navigate to such URLs, a user opening View Source could have inadvertently leaked their IP address. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
2021-01-07T14:15:12.453
2024-11-21T05:26:47.457
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:N/A:N
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mozilla | firefox | < 84.0 | Yes |
| Application | mozilla | firefox_esr | < 78.6.0 | Yes |
| Application | mozilla | thunderbird | < 78.6.0 | Yes |