CVE-2023-23602: Content Security Policy wasn't being correctly applied to WebSockets in WebWorkers
A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-23602?
CVE-2023-23602 is a vulnerability that allows connections to restricted origins from inside WebWorkers due to a mishandled security check when creating a WebSocket.
Which software products are affected by CVE-2023-23602?
Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102 are affected by CVE-2023-23602.
What is the severity of CVE-2023-23602?
CVE-2023-23602 has a severity level of medium (6.5).
How can I fix CVE-2023-23602?
To fix CVE-2023-23602, update Firefox to version 109 or later, Thunderbird to version 102.7 or later, or Firefox ESR to version 102 or later.
Where can I find more information about CVE-2023-23602?
You can find more information about CVE-2023-23602 on the Mozilla website: [mfsa2023-01](https://www.mozilla.org/security/advisories/mfsa2023-01/), [mfsa2023-03](https://www.mozilla.org/security/advisories/mfsa2023-03/), [mfsa2023-02](https://www.mozilla.org/security/advisories/mfsa2023-02/).