CVE-2023-25729Incorrect Authorization in Mozilla Firefox

Severity
8.8HIGHNVD
OSV6.5
EPSS
0.1%
top 68.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 2

Description

Permission prompts for opening external schemes were only shown for ContentPrincipals resulting in extensions being able to open them without user interaction via ExpandedPrincipals. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified110
NVDmozilla/firefox< 110.0
CVEListV5mozilla/firefox_esrunspecified102.8
NVDmozilla/firefox_esr< 102.8
Ubuntumozilla/firefox< 110.0+build3-0ubuntu0.18.04.1+3

🔴Vulnerability Details

6
OSV
CVE-2023-25729: Permission prompts for opening external schemes were only shown for ContentPrincipals resulting in extensions being able to open them without user int2023-06-02
GHSA
GHSA-vhjv-4vf6-mc9x: Permission prompts for opening external schemes were only shown for ContentPrincipals resulting in extensions being able to open them without user int2023-06-02
CVEList
CVE-2023-25729: Permission prompts for opening external schemes were only shown for ContentPrincipals resulting in extensions being able to open them without user int2023-06-02
OSV
thunderbird vulnerabilities2023-03-13
OSV
firefox regressions2023-03-01

📋Vendor Advisories

7
Ubuntu
Thunderbird vulnerabilities2023-03-13
Ubuntu
Firefox vulnerabilities2023-02-20
Red Hat
Mozilla: Extensions could have opened external schemes without user knowledge2023-02-14
Debian
CVE-2023-25729: firefox - Permission prompts for opening external schemes were only shown for <code>Conten...2023
Mozilla
Mozilla Foundation Security Advisory 2023-06: CVE-2023-25729
CVE-2023-25729 — Incorrect Authorization in Mozilla | cvebase