« Volver al listado

CVE-2020-15682

Estado: ModificadaMedia (6.5)—

Cuando se hacía clic en un enlace a un protocolo externo, se presentaba un mensaje que le permitía al usuario elegir en qué aplicación lo abriera. Un atacante podía inducir que ese mensaje se asociara con un origen que no controlaba, lo que resultaba en un ataque de suplantación de identidad. Esto se corrigió cambiando las indicaciones del protocolo externo para que sean tab-modal y, al mismo tiempo, se aseguró de que no pudieran asociarse incorrectamente con un origen diferente. Esta vulnerabilidad afecta a Firefox versiones anteriores a 82

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-15682",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@mozilla.org",
      "affectedData": [
        {
          "vendor": "Mozilla",
          "product": "Firefox",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "82",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-10-22T21:15:13.433",
  "references": [
    {
      "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1636654",
      "tags": [
        "Issue Tracking",
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "security@mozilla.org"
    },
    {
      "url": "https://www.mozilla.org/security/advisories/mfsa2020-45/",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "security@mozilla.org"
    },
    {
      "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1636654",
      "tags": [
        "Issue Tracking",
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.mozilla.org/security/advisories/mfsa2020-45/",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-346"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an origin they didn't control, resulting in a spoofing attack. This was fixed by changing external protocol prompts to be tab-modal while also ensuring they could not be incorrectly associated with a different origin. This vulnerability affects Firefox < 82."
    },
    {
      "lang": "es",
      "value": "Cuando se hacía clic en un enlace a un protocolo externo, se presentaba un mensaje que le permitía al usuario elegir en qué aplicación lo abriera. Un atacante podía inducir que ese mensaje se asociara con un origen que no controlaba, lo que resultaba en un ataque de suplantación de identidad.&#xa0;Esto se corrigió cambiando las indicaciones del protocolo externo para que sean tab-modal y, al mismo tiempo, se aseguró de que no pudieran asociarse incorrectamente con un origen diferente.&#xa0;Esta vulnerabilidad afecta a Firefox versiones anteriores a 82"
    }
  ],
  "lastModified": "2026-06-17T02:57:02.723",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A99DBC67-F226-4E09-B6C2-1B4346AEC802",
              "versionEndExcluding": "82.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@mozilla.org"
}