First published: Tue Jul 04 2023(Updated: )
When Firefox is configured to block storage of all cookies, it was still possible to store data in localstorage by using an iframe with a source of 'about:blank'. This could have led to malicious websites storing tracking data without permission. This vulnerability affects Firefox < 115.
Credit: security@mozilla.org security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/firefox | <115.0-1 | 115.0-1 |
ubuntu/firefox | <115.0+ | 115.0+ |
Mozilla Firefox | <115 | 115 |
Mozilla Firefox | <115.0 | |
debian/firefox | 123.0-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2023-3482.
The severity level of CVE-2023-3482 is medium.
This vulnerability affects Firefox versions prior to 115.
Data can be stored in localstorage by using an iframe with a source of 'about:blank', even when blocking cookies.
Yes, you can find more information about this vulnerability at the following links: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1839464), [Mozilla Security Advisories](https://www.mozilla.org/security/advisories/mfsa2023-22/), [Launchpad](https://launchpad.net/bugs/cve/CVE-2023-3482).