CVE Vulnerabilities

CVE-2023-23603

Published: Jun 02, 2023 | Modified: Jun 08, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Regular expressions used to filter out forbidden properties and values from style directives in calls to console.log werent accounting for external URLs. Data could then be potentially exfiltrated from the browser. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla * 109.0 (excluding)
Firefox_esr Mozilla * 102.7 (excluding)
Thunderbird Mozilla * 102.7 (excluding)

References