The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in the disclosure of local files. External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2020-17/#CVE-2020-12392
Acknowledgments: Name: the Mozilla project Upstream: Ophir LOJKINE
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions Via RHSA-2020:2033 https://access.redhat.com/errata/RHSA-2020:2033
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.1 Extended Update Support Via RHSA-2020:2032 https://access.redhat.com/errata/RHSA-2020:2032
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:2031 https://access.redhat.com/errata/RHSA-2020:2031
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-12392
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:2037 https://access.redhat.com/errata/RHSA-2020:2037
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2020:2036 https://access.redhat.com/errata/RHSA-2020:2036
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions Via RHSA-2020:2048 https://access.redhat.com/errata/RHSA-2020:2048
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.1 Extended Update Support Via RHSA-2020:2047 https://access.redhat.com/errata/RHSA-2020:2047
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:2046 https://access.redhat.com/errata/RHSA-2020:2046
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2020:2049 https://access.redhat.com/errata/RHSA-2020:2049
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:2050 https://access.redhat.com/errata/RHSA-2020:2050