First published: Tue Nov 21 2023(Updated: )
If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked the user into clicking to grant an HTTPS-only exception if they could get the user to participate in a clicking game. This vulnerability affects Firefox < 120.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/firefox | <120.0+ | 120.0+ |
Mozilla Firefox | <120 | 120 |
Mozilla Firefox | <120.0 | |
debian/firefox | 123.0-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-6211
Firefox < 120
By tricking the user into clicking to grant an HTTPS-only exception during a clicking game
Low
You can find more information about this vulnerability on the Mozilla website and bugzilla.mozilla.org.