CVE-2023-5725: Medium severity thunderbird vulnerability
A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-5725?
The severity of CVE-2023-5725 is medium.
How does CVE-2023-5725 affect Mozilla Firefox?
CVE-2023-5725 affects Mozilla Firefox version up to exclusive 119 and Mozilla Firefox ESR version up to exclusive 115.4.
Can a malicious WebExtension collect sensitive user data through CVE-2023-5725?
Yes, a malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data.
How can I mitigate the vulnerability CVE-2023-5725?
To mitigate CVE-2023-5725, update Mozilla Firefox to version 119 or later and Mozilla Firefox ESR to version 115.4 or later.
Where can I find more information about CVE-2023-5725?
You can find more information about CVE-2023-5725 on the Mozilla Bugzilla website and the Mozilla Security Advisories website.