Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*, +1 more
- < 140
A vulnerability in Mozilla Firefox allows a webpage with an invalid TLS certificate to present a WebAuthn challenge, which the user is prompted to complete. This behavior contradicts the WebAuthn specification, which mandates a secure transport without errors. The issue arises when a user accepts an exception for the invalid certificate. This vulnerability affects Firefox versions prior to 140.
Exploitation of this vulnerability could lead to unauthorized WebAuthn assertions, allowing users to inadvertently complete authentication challenges on insecure websites.
Users can update to Firefox 140 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.