An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying on sandbox configurations that allowed popups and hosted arbitrary content. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2020-08-10T17:43:24

Updated: 2024-08-04T13:22:30.658Z

Reserved: 2020-07-10T00:00:00

Link: CVE-2020-15653

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-08-10T18:15:12.373

Modified: 2023-02-02T22:19:14.043

Link: CVE-2020-15653

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-07-28T00:00:00Z

Links: CVE-2020-15653 - Bugzilla