CVE-2023-25729: High severity thunderbird vulnerability
Last updated 24 July 2024
Other sources
Permission prompts for opening external schemes were only shown for ContentPrincipals resulting in extensions being able to open them without user interaction via ExpandedPrincipals. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-06/#CVE-2023-25729
— Red Hat
Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them without user interaction via <code>ExpandedPrincipals</code>. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Permission prompts for opening external schemes were only shown for ContentPrincipals resulting in extensions being able to open them without user interaction via ExpandedPrincipals. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system.
The Mozilla Foundation Security Advisory describes this flaw as: Permission prompts for opening external schemes were only shown for ContentPrincipals resulting in extensions being able to open them without user interaction via ExpandedPrincipals. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-25729?
CVE-2023-25729 is a vulnerability that allows extensions in Mozilla Thunderbird and Firefox to open external schemes without user interaction.
Which software is affected by CVE-2023-25729?
Mozilla Thunderbird and Firefox versions up to 102.8 are affected, as well as specific versions of Red Hat Firefox and Thunderbird packages, Ubuntu Firefox and Thunderbird packages, and Debian Firefox, Thunderbird, and Firefox ESR packages.
What is the severity of CVE-2023-25729?
The severity of CVE-2023-25729 is high, with a CVSS score of 8.8.
How can I fix CVE-2023-25729?
To fix CVE-2023-25729, update Mozilla Thunderbird and Firefox to version 102.8 or higher, or install the respective updated packages for Red Hat, Ubuntu, and Debian.
Where can I find more information about CVE-2023-25729?
You can find more information about CVE-2023-25729 in the Mozilla Bugzilla and Mozilla Security Advisories.