CVE-2023-1384: XSS
The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to be run
This issue affects:
Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-1384.
What is the title of the vulnerability?
The title of the vulnerability is 'The setMediaSource function on the amzn.thin.pl service does not sanitize the source parameter allowing for arbitrary javascript code to be run'.
Which devices are affected by this vulnerability?
This vulnerability affects Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5 and Insignia TV with FireOS versions prior to 7.6.3.3.
What is the severity of CVE-2023-1384?
The severity of CVE-2023-1384 is medium with a severity value of 6.1.
How can I fix this vulnerability?
To fix this vulnerability, update your Amazon Fire TV Stick 3rd gen to version 6.2.9.5 or later, and update your Insignia TV with FireOS to version 7.6.3.3 or later.