CVE-2023-6211: Medium severity firefox vulnerability
Published Nov 21, 2023
·Updated
If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked the user into clicking to grant an HTTPS-only exception if they could get the user to participate in a clicking game. This vulnerability affects Firefox < 120.
Affected Software
4 affected componentsFixes available
ubuntu/firefox<120.0+
120.0+
debian/firefox
123.0-1
Mozilla Firefox<120
120
Mozilla Firefox<120.0
Event History
Nov 21, 2023
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·02:28 PM
Data Sourced
via MITRE·02:28 PM
DescriptionWeakness
Jan 12, 2024
Data Sourced
via Launchpad·12:29 AM
Description
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
CVE-2023-6211
2
Which version of Firefox is affected by this vulnerability?
Firefox < 120
3
How can an attacker exploit this vulnerability?
By tricking the user into clicking to grant an HTTPS-only exception during a clicking game
4
What is the severity level of this vulnerability?
Low
5
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Mozilla website and bugzilla.mozilla.org.