CVE-2023-23598Multiple Interpretations of UI Input in Mozilla Firefox

Severity
6.5MEDIUMNVD
EPSS
0.2%
top 58.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 2

Description

Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website could arbitrarily read a file via a call to `DataTransfer.setData`. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified109
NVDmozilla/firefox< 109.0
CVEListV5mozilla/firefox_esrunspecified102.7
NVDmozilla/firefox_esr< 102.7
Ubuntumozilla/firefox< 109.0+build2-0ubuntu0.18.04.1+3

🔴Vulnerability Details

6
OSV
CVE-2023-23598: Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a we2023-06-02
CVEList
Arbitrary file read from GTK drag and drop on Linux2023-06-02
GHSA
GHSA-h2qp-p99q-hmrr: Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a we2023-06-02
OSV
firefox regressions2023-02-06
OSV
thunderbird vulnerabilities2023-02-06

📋Vendor Advisories

7
Ubuntu
Thunderbird vulnerabilities2023-02-06
Ubuntu
Firefox vulnerabilities2023-01-23
Red Hat
Mozilla: Arbitrary file read from GTK drag and drop on Linux2023-01-17
Debian
CVE-2023-23598: firefox - Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK tr...2023
Mozilla
Mozilla Foundation Security Advisory 2023-01: CVE-2023-23598
CVE-2023-23598 — Multiple Interpretations of UI Input | cvebase