CVE-2021-29965

Description

A malicious website that causes an HTTP Authentication dialog to be spawned could trick the built-in password manager to suggest passwords for the currently active website instead of the website that triggered the dialog. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Score
Exploitation Probability
0.304

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities fixed in Mozilla Firefox (x64) (89.0)Windows
Multiple vulnerabilities fixed in Mozilla Firefox (89.0)Windows
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (89.0)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (89.0.2)Mac
Vulnerabilities CVE-2021-29963,CVE-2021-29964,CVE-2021-29965 are affected in Mozilla Firefox for Mac 88.9Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-319856Mozilla Firefox (x64) (89.0)
PATCH-319855Mozilla Firefox (89.0)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-611870Mozilla Firefox For Mac (142.0.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234