Security Advisory
CVE-2020-6823
9.8
CRITICAL
Vulnerability Description
A malicious extension could have called
browser.identity.launchWebAuthFlow, controlling the redirect_uri, and through the Promise returned, obtain the Auth code and gain access to the user's account at the service provider. This vulnerability affects Firefox < 75.
Published Date
April 24, 2020
Official Source
NIST NVD Advisory