First published: Tue Feb 14 2023(Updated: )
Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in privileged code. This vulnerability affects Firefox < 110.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <110 | 110 |
Mozilla Firefox | <110.0 | |
ubuntu/firefox | <110.0+ | 110.0+ |
ubuntu/firefox | <110.0+ | 110.0+ |
ubuntu/firefox | <110.0-1 | 110.0-1 |
debian/firefox | 129.0-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-25731 is a vulnerability in Firefox < 110 that allows query parameters in URLs to potentially overwrite global objects in privileged code.
CVE-2023-25731 affects Firefox versions earlier than 110.
CVE-2023-25731 has a low severity rating.
To fix CVE-2023-25731, update Firefox to version 110 or higher.
You can find more information about CVE-2023-25731 in the Mozilla Security Advisory (MFSA2023-05), Bugzilla entry, and the corresponding CVE reference.