CVE-2023-28164: Medium severity thunderbird vulnerability
A flaw was found in Mozilla. The Mozilla Foundation Security Advisory described the issue of dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks.
Other sources
Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-10/#CVE-2023-28164
— Red Hat
Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-28164?
CVE-2023-28164 is a vulnerability that allows dragging a URL from a cross-origin iframe that was removed during the drag, which could lead to user confusion and website spoofing attacks.
Which software products are affected by CVE-2023-28164?
Mozilla Firefox, Mozilla Thunderbird, and their respective packages in Red Hat and Ubuntu are affected by CVE-2023-28164.
What is the severity level of CVE-2023-28164?
CVE-2023-28164 has a severity level of medium, with a CVSS score of 6.1.
How can I fix CVE-2023-28164?
To fix CVE-2023-28164, update your Mozilla Firefox or Mozilla Thunderbird to the recommended versions provided by the vendor.
Where can I find more information about CVE-2023-28164?
You can find more information about CVE-2023-28164 at the following references: [Link 1](https://www.mozilla.org/security/advisories/mfsa2023-11/), [Link 2](https://bugzilla.mozilla.org/show_bug.cgi?id=1809122), [Link 3](https://www.mozilla.org/security/advisories/mfsa2023-10/).