Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically prepared request, lead to remote code execution.
References
Link Resource
http://www.openwall.com/lists/oss-security/2022/02/07/3 Mailing List Third Party Advisory
https://github.com/mozilla/geckodriver/releases/tag/v0.27.0 Release Notes Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mozilla

Published: 2021-07-20T11:24:16

Updated: 2022-02-08T00:06:09

Reserved: 2020-07-10T00:00:00


Link: CVE-2020-15660

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-07-20T12:15:07.657

Modified: 2022-02-22T14:28:32.633


Link: CVE-2020-15660

JSON object: View

cve-icon Redhat Information

No data.

CWE