CVE-2021-23999Improper Privilege Management in Mozilla Firefox

Severity
8.8HIGHNVD
OSV7.4
EPSS
0.2%
top 64.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 24
Latest updateMay 24

Description

If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified88
NVDmozilla/firefox< 88.0
CVEListV5mozilla/firefox_esrunspecified78.10
NVDmozilla/firefox_esr< 78.10
Ubuntumozilla/firefox< 88.0+build2-0ubuntu0.16.04.1+2

🔴Vulnerability Details

6
GHSA
GHSA-f4hx-f2xg-27cv: If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges th2022-05-24
OSV
thunderbird vulnerabilities2021-06-25
OSV
CVE-2021-23999: If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges th2021-06-24
CVEList
CVE-2021-23999: If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges th2021-06-24
OSV
thunderbird vulnerabilities2021-06-22

📋Vendor Advisories

8
Ubuntu
Thunderbird vulnerabilities2021-06-25
Ubuntu
Thunderbird vulnerabilities2021-06-22
Ubuntu
Firefox vulnerabilities2021-04-26
Red Hat
Mozilla: Blob URLs may have been granted additional privileges2021-04-19
Debian
CVE-2021-23999: firefox - If a Blob URL was loaded through some unusual user interaction, it could have be...2021
CVE-2021-23999 — Improper Privilege Management | cvebase