First published: Tue Mar 14 2023(Updated: )
When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would have resolved those in the context of the current user. <br>*This bug only affects Firefox on Windows. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | <102.9 | 102.9 |
Mozilla Firefox | <111.0 | |
Mozilla Firefox ESR | <102.9 | |
Mozilla Thunderbird | <102.9 | |
<111 | 111 | |
<102.9 | 102.9 | |
<102.9 | 102.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-28163 is a vulnerability that affects Firefox on Windows when downloading files through the Save As dialog.
Firefox versions up to exclusive version 111, Firefox ESR versions up to exclusive version 102.9, and Thunderbird up to exclusive version 102.9 are affected by CVE-2023-28163.
CVE-2023-28163 has a medium severity rating with a CVSS score of 4.
CVE-2023-28163 allows environment variable names in suggested filenames to be resolved in the context of the current user, potentially leading to information disclosure.
To fix CVE-2023-28163, update your Firefox, Firefox ESR, or Thunderbird software to the latest version available.