Fedora Account System
Red Hat Associate
Red Hat Customer
A reflected XSS vulnerability exists within the gateway, allowing an attacker to craft a specialized URL which could steal the user's authentication token. When combined with CVE-2020-6803, an attacker could fully compromise the system. References: https://github.com/mozilla-iot/gateway/pull/2446
Created mozilla-iot-gateway tracking bugs for this issue: Affects: fedora-all [bug 1829278]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.