CVE-2020-15653: Canonical Ubuntu Linux
Medium severity, CVSS 6.5. EPSS: 1.4% chance of exploitation in the next 30 days.
An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying on sandbox configurations that allowed popups and hosted arbitrary content. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 20.04 only
- Mozilla Firefox: before 79.0 (fixed in 79.0)
- Mozilla Firefox ESR: before 78.1 (fixed in 78.1)
- Mozilla Thunderbird: before 78.1 (fixed in 78.1)
Published 2020-08-10. Last modified 2026-06-17.