CVE Published: 26/02/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: mozilla |
Vendor: Mozilla |
Product: Firefox Status : PUBLISHED
CVE-2021-23971 Description
When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redirect\'s Referrer-Policy. This would have potentially resulted in more information than intended by the original origin being provided to the destination of the redirect. This vulnerability affects Firefox < 86.
CWE-ID: CWE Name: A website
s Referrer-Policy could have been be overridden, potentially resulting in the full URL being sent as a Referrer Source: Mozilla
Common Attack Pattern Enumeration and Classification (CAPEC)