CVE-2023-4045: Medium severity thunderbird vulnerability
Last updated 24 July 2024
Other sources
Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-4045?
CVE-2023-4045 is a vulnerability that affects Firefox versions below 116, Firefox ESR versions below 102.14, and Thunderbird versions below 115.1. It allows cross-origin tainting and unauthorized access to image data.
How does CVE-2023-4045 impact users?
CVE-2023-4045 can be exploited to bypass same-origin policy and potentially access image data from another site.
What is the severity of CVE-2023-4045?
CVE-2023-4045 has a severity rating of 5.3 (High).
Which software versions are affected by CVE-2023-4045?
Firefox versions below 116, Firefox ESR versions below 102.14, and Thunderbird versions below 115.1 are affected by CVE-2023-4045.
How can I mitigate the CVE-2023-4045 vulnerability?
To mitigate CVE-2023-4045, users should update their Firefox and Thunderbird installations to versions 116 and 115.1 respectively.