Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-5722
HistoryOct 25, 2023 - 12:00 a.m.

CVE-2023-5722

2023-10-2500:00:00
ubuntu.com
ubuntu.com
8
security vulnerability
iterative requests
opaque response
server-supplied vary header
firefox < 119
ubuntu 22.04
python-pip package
requests binaries
jammy and later
spidermonkey javascript engine

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

20.6%

Using iterative requests an attacker was able to learn the size of an
opaque response, as well as the contents of a server-supplied Vary header.
This vulnerability affects Firefox < 119.

Notes

Author Note
tyhicks mozjs contains a copy of the SpiderMonkey JavaScript engine
mdeslaur starting with Ubuntu 22.04, the firefox package is just a script that installs the Firefox snap On focal and earlier, the python-pip package bundles requests binaries when built. After updating requests, a no-change rebuild of python-pip is required. On jammy and later, requests is bundled in the python-pip package and needs to be patched.

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

20.6%