Vulnerability Details CVE-2021-29965
A malicious website that causes an HTTP Authentication dialog to be spawned could trick the built-in password manager to suggest passwords for the currently active website instead of the website that triggered the dialog. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.0%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 4.3
Products affected by CVE-2021-29965
-
cpe:2.3:a:mozilla:firefox:80.0
-
cpe:2.3:a:mozilla:firefox:83.0
-
cpe:2.3:a:mozilla:firefox:84.0
-
cpe:2.3:a:mozilla:firefox:84.1.3