CVE-2023-34415: Medium severity Mozilla Firefox vulnerability
When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that document in the same process as the site that issued the redirect. This bypassed the site-isolation protections against Spectre-like attacks on sites that host an "open redirect". Firefox no longer follows HTTP redirects to data: URLs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/firefoxto a version that resolves this vulnerability.Fixed in 114.0+ - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 123.0-1 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 114
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-34415?
The severity of CVE-2023-34415 is medium.
Which software is affected by CVE-2023-34415?
Mozilla Firefox versions up to and including 114, Ubuntu Firefox versions 114.0+ and Debian Firefox versions up to and including 117.0.1-1 are affected by CVE-2023-34415.
How can I fix CVE-2023-34415?
Ensure that you update Mozilla Firefox to version 115 or higher.
Is there any reference for CVE-2023-34415?
Yes, you can find references for CVE-2023-34415 at the following links: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1811999), [Mozilla Security Advisory](https://www.mozilla.org/security/advisories/mfsa2023-20/), [Launchpad](https://launchpad.net/bugs/cve/CVE-2023-34415).