Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-5725
HistoryOct 25, 2023 - 12:00 a.m.

CVE-2023-5725

2023-10-2500:00:00
ubuntu.com
ubuntu.com
12
webextension vulnerability
firefox
firefox esr
thunderbird
arbitrary urls
sensitive data collection

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

29.5%

A malicious installed WebExtension could open arbitrary URLs, which under
the right circumstance could be leveraged to collect sensitive user data.
This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and
Thunderbird < 115.4.1.

Notes

Author Note
tyhicks mozjs contains a copy of the SpiderMonkey JavaScript engine
mdeslaur starting with Ubuntu 22.04, the firefox package is just a script that installs the Firefox snap

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

29.5%