First published: Tue Apr 11 2023(Updated: )
When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, when it should have silently failed. This could have led to a desynchronization in expected results when reading from the secure cookie. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <112 | 112 |
All of | ||
Mozilla Firefox | =112 | |
Google Android | ||
All of | ||
Mozilla Focus | =112 | |
Google Android | ||
Mozilla Firefox | <112.0 | |
Mozilla Firefox ESR | <102.10 | |
Mozilla Focus | <112.0 | |
ubuntu/firefox | <112.0+ | 112.0+ |
ubuntu/firefox | <112.0+ | 112.0+ |
ubuntu/firefox | <112.0-1 | 112.0-1 |
debian/firefox | 128.0.3-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this vulnerability is CVE-2023-29547.
The severity level of CVE-2023-29547 is low.
The software versions affected by CVE-2023-29547 are Firefox for Android versions 112.0+ and Firefox for Ubuntu versions 112.0+.
To fix CVE-2023-29547, update your Firefox for Android or Firefox for Ubuntu to version 112.0+.
You can find more information about CVE-2023-29547 on the Mozilla Security Advisories page.