CVE-2023-6209: Path Traversal
Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-6209?
CVE-2023-6209 is a vulnerability that affects Firefox versions less than 120, Firefox versions less than 115.5, and Thunderbird versions less than 115.5.0. It allows for path traversal in the URL path, which can override the specified host and potentially lead to security issues.
How does CVE-2023-6209 affect web sites?
CVE-2023-6209 can contribute to security problems in web sites as it allows for the override of specified hosts through path traversal in the URL path.
What is the severity of CVE-2023-6209?
CVE-2023-6209 has a severity level of medium with a severity value of 4 on a scale of 1-5.
Which software versions are affected by CVE-2023-6209?
Firefox versions less than 120, Firefox versions less than 115.5, and Thunderbird versions less than 115.5.0 are affected by CVE-2023-6209.
How can I remediate CVE-2023-6209?
To remediate CVE-2023-6209, ensure that you update Firefox to version 120 or above, Firefox to version 115.5 or above, and Thunderbird to version 115.5.0 or above.