CVE-2023-37204: Medium severity Mozilla Firefox vulnerability
A website could have obscured the fullscreen notification by using an option element by introducing lag via an expensive computational function. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/firefoxto a version that resolves this vulnerability.Fixed in 115.0-1 - Upgrade
Upgrade
ubuntu/firefoxto a version that resolves this vulnerability.Fixed in 115.0+ - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 123.0-1 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 115
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-37204?
CVE-2023-37204 is a vulnerability that allows a website to obscure the fullscreen notification by introducing lag, leading to user confusion and possible spoofing attacks.
Which software is affected by CVE-2023-37204?
Firefox versions prior to 115 are affected by CVE-2023-37204.
What is the severity of CVE-2023-37204?
The severity of CVE-2023-37204 is medium with a severity value of 4.
How can I fix CVE-2023-37204?
To fix CVE-2023-37204, update your Firefox browser to version 115 or higher.
Where can I find more information about CVE-2023-37204?
You can find more information about CVE-2023-37204 at the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1832195), [Mozilla Security Advisory](https://www.mozilla.org/security/advisories/mfsa2023-22/), [Launchpad](https://launchpad.net/bugs/cve/CVE-2023-37204)