CVE-2021-23953 — Inclusion of Functionality from Untrusted Control Sphere in Mozilla Firefox
Severity
4.3MEDIUMNVD
EPSS
0.4%
top 40.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 26
Latest updateMay 24
Description
If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as chunked data. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4
Affected Packages7 packages
🔴Vulnerability Details
3GHSA▶
GHSA-8w82-qfxh-635c: If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is se↗2022-05-24
CVEList▶
CVE-2021-23953: If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is se↗2021-02-26
OSV▶
CVE-2021-23953: If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is se↗2021-02-26
📋Vendor Advisories
7Debian▶
CVE-2021-23953: firefox - If a user clicked into a specifically crafted PDF, the PDF reader could be confu...↗2021