CVE Vulnerabilities

CVE-2023-4583

Published: Sep 11, 2023 | Modified: Sep 14, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

When checking if the Browsing Context had been discarded in HttpBaseChannel, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private session had ended. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla * 117.0 (excluding)
Firefox_esr Mozilla * 115.2 (excluding)
Thunderbird Mozilla * 115.2 (excluding)

References