First published: Tue Nov 21 2023(Updated: )
Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/firefox | <115.5 | 115.5 |
redhat/thunderbird | <115.5 | 115.5 |
ubuntu/firefox | <120.0+ | 120.0+ |
ubuntu/thunderbird | <1:115.5.0+ | 1:115.5.0+ |
ubuntu/thunderbird | <1:115.5.0+ | 1:115.5.0+ |
ubuntu/thunderbird | <1:115.5.0+ | 1:115.5.0+ |
ubuntu/thunderbird | <1:115.5.0+ | 1:115.5.0+ |
Mozilla Thunderbird | <115.5 | 115.5 |
Mozilla Firefox ESR | <115.5 | 115.5 |
Mozilla Firefox | <120 | 120 |
Mozilla Firefox | <120.0 | |
Mozilla Firefox ESR | <115.5.0 | |
Mozilla Thunderbird | <115.5 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Debian Debian Linux | =12.0 | |
debian/firefox | 123.0-1 | |
debian/firefox-esr | <=91.12.0esr-1~deb10u1 | 115.8.0esr-1~deb10u1 115.7.0esr-1~deb11u1 115.8.0esr-1~deb11u1 115.7.0esr-1~deb12u1 115.8.0esr-1~deb12u1 115.8.0esr-1 |
debian/thunderbird | <=1:91.12.0-1~deb10u1 | 1:115.8.0-1~deb10u1 1:115.7.0-1~deb11u1 1:115.8.0-1~deb11u1 1:115.7.0-1~deb12u1 1:115.8.0-1~deb12u1 1:115.7.0-1 1:115.8.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2023-6209 is a vulnerability that affects Firefox versions less than 120, Firefox versions less than 115.5, and Thunderbird versions less than 115.5.0. It allows for path traversal in the URL path, which can override the specified host and potentially lead to security issues.
CVE-2023-6209 can contribute to security problems in web sites as it allows for the override of specified hosts through path traversal in the URL path.
CVE-2023-6209 has a severity level of medium with a severity value of 4 on a scale of 1-5.
Firefox versions less than 120, Firefox versions less than 115.5, and Thunderbird versions less than 115.5.0 are affected by CVE-2023-6209.
To remediate CVE-2023-6209, ensure that you update Firefox to version 120 or above, Firefox to version 115.5 or above, and Thunderbird to version 115.5.0 or above.