First published: Wed May 03 2023(Updated: )
The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to be run This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3.
Credit: cve-requests@bitdefender.com
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Fire OS | <6.2.9.5 | |
Amazon Fire TV Stick 3rd gen | ||
Amazon Fire OS | <7.6.3.3 | |
Bestbuy Insignia Tv |
An automatic firmware update to the following versions fixes the issue: Amazon Fire TV Stick 3rd gen version 6.2.9.5 Insignia TV with FireOS version 7.6.3.3
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-1384.
The title of the vulnerability is 'The setMediaSource function on the amzn.thin.pl service does not sanitize the source parameter allowing for arbitrary javascript code to be run'.
This vulnerability affects Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5 and Insignia TV with FireOS versions prior to 7.6.3.3.
The severity of CVE-2023-1384 is medium with a severity value of 6.1.
To fix this vulnerability, update your Amazon Fire TV Stick 3rd gen to version 6.2.9.5 or later, and update your Insignia TV with FireOS to version 7.6.3.3 or later.