CVE-2023-5721: Medium severity thunderbird vulnerability
Published Oct 24, 2023
·Updated
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay.
Affected Software
13 affected componentsFixes available
redhat/firefox<115.4
115.4
redhat/thunderbird<115.4.1
115.4.1
debian/firefox
130.0-2
debian/firefox-esr
115.14.0esr-1~deb11u1115.15.0esr-1~deb11u1115.14.0esr-1~deb12u1115.15.0esr-1~deb12u1115.15.0esr-1
debian/thunderbird
1:115.12.0-1~deb11u11:115.15.0-1~deb11u11:115.12.0-1~deb12u11:115.15.0-1~deb12u11:128.2.0esr-1
Mozilla Thunderbird<115.4.1
115.4.1
Mozilla Firefox<119
119
Mozilla Firefox ESR<115.4
115.4
Mozilla Firefox<119.0
Mozilla Firefox ESR<115.4
Mozilla Thunderbird<115.4.1
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Event History
Oct 24, 2023
CVE Published
via Mozilla·12:00 AM
CVE Published
via MITRE·12:47 PM
Data Sourced
via MITRE·12:47 PM
DescriptionWeakness
Jan 12, 2024
Data Sourced
via Launchpad·12:28 AM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·04:18 AM
RemedyDescriptionSeverityAffected Software
May 24, 57290
Event
via FIRST·01:24 AM
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-5721.
2
What is the title of the vulnerability?
The title of the vulnerability is 'It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally…'
3
How does the vulnerability occur?
The vulnerability occurs due to an insufficient activation-delay for certain browser prompts and dialogs.
4
Which software products are affected by this vulnerability?
The Mozilla Firefox versions up to 119 and Mozilla Firefox ESR versions up to 115.4 are affected.
5
What is the severity level of this vulnerability?
The severity level of this vulnerability is high with a severity value of 7 on a scale of 1-10.