CVE-2023-23603 Vulnerability Details

  /     /     /  

CVE-2023-23603 Metadata Quick Info

CVE Published: 02/06/2023 | CVE Updated: 02/08/2024 | CVE Year: 2023
Source: mozilla | Vendor: Mozilla | Product: Firefox
Status : PUBLISHED

CVE-2023-23603 Description

Regular expressions used to filter out forbidden properties and values from style directives in calls to console.log weren\'t accounting for external URLs. Data could then be potentially exfiltrated from the browser. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Calls to console.log allowed bypasing Content Security Policy via format directive
Source: Mozilla

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).