Security Advisory

CVE-2020-26973

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-01-07 13:53:21
Last updated 2024-08-04 16:03:23
Assigner mozilla
State PUBLISHED

Description

Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer bypass. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.