Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-32212
HistoryMay 10, 2023 - 12:00 a.m.

CVE-2023-32212

2023-05-1000:00:00
ubuntu.com
ubuntu.com
13
attack position obscure
datalist element
firefox esr
thunderbird
javascript engine
ubuntu 22.04
firefox snap
security vulnerability

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

EPSS

0.001

Percentile

45.5%

An attacker could have positioned a <code>datalist</code> element to
obscure the address bar. This vulnerability affects Firefox < 113, Firefox
ESR < 102.11, and Thunderbird < 102.11.

Notes

Author Note
tyhicks mozjs contains a copy of the SpiderMonkey JavaScript engine
mdeslaur starting with Ubuntu 22.04, the firefox package is just a script that installs the Firefox snap
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchfirefox< 113.0+build2-0ubuntu0.18.04.1UNKNOWN
ubuntu20.04noarchfirefox< 113.0+build2-0ubuntu0.20.04.1UNKNOWN
ubuntu18.04noarchmozjs38< anyUNKNOWN
ubuntu18.04noarchmozjs52< anyUNKNOWN
ubuntu20.04noarchmozjs52< anyUNKNOWN
ubuntu20.04noarchmozjs68< anyUNKNOWN
ubuntu22.04noarchmozjs78< anyUNKNOWN
ubuntu22.04noarchmozjs91< anyUNKNOWN
ubuntu18.04noarchthunderbird< 1:102.11.0+build1-0ubuntu0.18.04.1UNKNOWN
ubuntu20.04noarchthunderbird< 1:102.11.0+build1-0ubuntu0.20.04.1UNKNOWN
Rows per page:
1-10 of 131

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

EPSS

0.001

Percentile

45.5%