Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefoxUpgrade firefox-esrUpgrade thunderbirdUpgrade librewolf | Aug 22, 2024 | Oct 1, 2020 |
| Amazon Linux Ami 2 | — | Upgrade thunderbirdUpgrade thunderbird-debuginfo | Dec 10, 2020 | Oct 1, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Oct 1, 2020 |
| Centos_linux | — | Upgrade firefox-debugsourceUpgrade thunderbird-debugsourceUpgrade thunderbirdUpgrade firefoxUpgrade thunderbird-debuginfoUpgrade firefox-debuginfo | Sep 25, 2020 | Sep 24, 2020 |
| Debian | — | Upgrade firefox-esrUpgrade thunderbird | Sep 30, 2020 | Sep 30, 2020 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird.Upgrade mail-client/thunderbird-bin.Upgrade www-client/firefox-bin.Upgrade www-client/firefox. | Oct 19, 2020 | Oct 1, 2020 |
| Mfsa2020 42 | — | Upgrade to Mozilla Firefox version 81.0Upgrade to the latest version of Mozilla Firefox | Sep 23, 2020 | Sep 22, 2020 |
| Mfsa2020 43 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 78.3 | Sep 23, 2020 | Sep 22, 2020 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 78.3Upgrade to the latest version of Mozilla Thunderbird | Sep 25, 2020 | Sep 22, 2020 |
| Oracle Solaris | — | Upgrade web/data/firefox-bookmarks to version 78.3.0-11.4.27.0.1.82.0 on Solaris 11.4Upgrade web/browser/firefox to version 78.3.0-11.4.27.0.1.82.0 on Solaris 11.4Upgrade mail/thunderbird to version 78.3.0-11.4.27.0.1.82.0 on Solaris 11.4 | Jan 19, 2021 | Oct 1, 2020 |
| Oracle_linux | — | Upgrade thunderbirdUpgrade firefox | Sep 25, 2020 | Sep 22, 2020 |
| Redhat_linux | — | Upgrade firefox-debuginfoNo solution existsUpgrade firefox-debugsourceUpgrade thunderbird-debuginfoUpgrade thunderbird-debugsourceUpgrade thunderbirdUpgrade firefox | Sep 25, 2020 | Sep 24, 2020 |
| Suse | — | Upgrade mozillafirefox-buildsymbolsUpgrade mozilla-nspr-develUpgrade MozillaFirefox-translations-otherUpgrade mozillafirefox-branding-upstreamUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefoxUpgrade MozillaThunderbird-translations-commonUpgrade MozillaFirefox-develUpgrade mozilla-nsprUpgrade MozillaThunderbird-translations-otherUpgrade mozilla-nspr-32bitUpgrade MozillaThunderbird | Sep 29, 2020 | Sep 24, 2020 |
| Ubuntu | — | Upgrade firefox | Sep 29, 2020 | Sep 24, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub