Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This vulnerability affects Firefox < 83.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mozilla
Published: 2020-12-09T00:24:00
Updated: 2024-08-04T16:03:23.155Z
Reserved: 2020-10-12T00:00:00
Link: CVE-2020-26962
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-12-09T01:15:13.347
Modified: 2024-11-21T05:20:35.223
Link: CVE-2020-26962
Redhat
No data.