If an attacker needed a user to load an insecure http:...
Moderate severity
Unreviewed
Published
Nov 21, 2023
to the GitHub Advisory Database
•
Updated Jan 7, 2024
Description
Published by the National Vulnerability Database
Nov 21, 2023
Published to the GitHub Advisory Database
Nov 21, 2023
Last updated
Jan 7, 2024
If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked the user into clicking to grant an HTTPS-only exception if they could get the user to participate in a clicking game. This vulnerability affects Firefox < 120.
References