First published: Tue Jan 17 2023(Updated: )
Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <102.7 | 102.7 |
<109 | 109 | |
<102.7 | 102.7 | |
<102.7 | 102.7 | |
Mozilla Firefox | <109.0 | |
Mozilla Firefox ESR | <102.7 | |
Mozilla Thunderbird | <102.7 | |
debian/firefox | 118.0.2-1 | |
debian/firefox-esr | <=91.12.0esr-1~deb10u1 | 115.3.1esr-1~deb10u1 102.15.0esr-1~deb11u1 115.3.1esr-1~deb11u1 102.15.1esr-1~deb12u1 115.3.0esr-1~deb12u1 115.3.0esr-1 |
debian/thunderbird | <=1:91.12.0-1~deb10u1 | 1:115.3.1-1~deb10u1 1:102.13.1-1~deb11u1 1:115.3.1-1~deb11u1 1:102.15.1-1~deb12u1 1:115.3.1-1~deb12u1 1:115.3.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-23601 is a vulnerability that allows navigations when dragging a URL from a cross-origin iframe into the same tab, which can lead to website spoofing attacks.
Firefox versions before 109, Thunderbird versions before 102.7, and Firefox ESR versions before 102.7 are affected by CVE-2023-23601.
CVE-2023-23601 has a severity rating of 6.5, which is considered medium.
To fix CVE-2023-23601 in Firefox, update to version 109 or later.
To fix CVE-2023-23601 in Thunderbird, update to version 102.7 or later.
To fix CVE-2023-23601 in Firefox ESR, update to version 102.7 or later.