CVE-2023-37206: Medium severity Mozilla Firefox vulnerability
Uploading files which contain symlinks may have allowed an attacker to trick a user into submitting sensitive data to a malicious website. This vulnerability affects Firefox < 115.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/firefoxto a version that resolves this vulnerability.Fixed in 115.0-1 - Upgrade
Upgrade
ubuntu/firefoxto a version that resolves this vulnerability.Fixed in 115.0+ - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 123.0-1 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 115
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2023-37206.
What software is affected by this security vulnerability?
Firefox versions prior to 115 are affected.
What is the severity of CVE-2023-37206?
The severity of this vulnerability is medium.
How can an attacker exploit this vulnerability?
An attacker can trick a user into submitting sensitive data to a malicious website by uploading files containing symlinks.
Where can I find more information about CVE-2023-37206?
You can find more information about this vulnerability in the following references: [link1](https://bugzilla.mozilla.org/show_bug.cgi?id=1813299), [link2](https://www.mozilla.org/security/advisories/mfsa2023-22/), [link3](https://launchpad.net/bugs/cve/CVE-2023-37206).