Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-05211
HistoryDec 30, 2022 - 12:00 a.m.

Mozilla Firefox permission permission and access control issue vulnerability (CNVD-2023-05211)

2022-12-3000:00:00
China National Vulnerability Database
www.cnvd.org.cn
17
mozilla firefox
permission
access control
vulnerability
extension updates
automatic updates
cnvd-2023-05211

0.001 Low

EPSS

Percentile

41.9%

Mozilla Firefox is an open source Web browser from the Mozilla Foundation in the U.S. A permission permission and access control issue vulnerability exists in Mozilla Firefox, which stems from the way Firefox handles extension updates. An attacker could use the vulnerability to trick victims into installing a specific type of browser extension and bypass the prompt to grant permission for new requests for new versions during automatic updates.