CVE-2023-6210: Medium severity firefox vulnerability
Published Nov 21, 2023
·Updated
When an https: web page created a pop-up from a "javascript:" URL, that pop-up was incorrectly allowed to load blockable content such as iframes from insecure http: URLs This vulnerability affects Firefox < 120.
Affected Software
4 affected componentsFixes available
ubuntu/firefox<120.0+
120.0+
debian/firefox
123.0-1
Mozilla Firefox<120
120
Mozilla Firefox<120.0
Event History
Nov 21, 2023
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·02:28 PM
Data Sourced
via MITRE·02:28 PM
DescriptionWeakness
Jan 12, 2024
Data Sourced
via Launchpad·12:29 AM
Description
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-6210.
2
Which web browser is affected by this vulnerability?
This vulnerability affects Mozilla Firefox version up to exclusive 120.
3
What is the severity of CVE-2023-6210?
The severity of CVE-2023-6210 is low.
4
How does this vulnerability affect web pages?
When an https: web page creates a pop-up from a "javascript:" URL, that pop-up is incorrectly allowed to load blockable content from insecure http: URLs.
5
How can I fix CVE-2023-6210?
To fix CVE-2023-6210, update Mozilla Firefox to version 120 or later.