CVE-2023-25741Observable Discrepancy in Mozilla Firefox

Severity
6.5MEDIUMNVD
OSV8.8
EPSS
0.2%
top 58.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 2

Description

When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until further review. This vulnerability affects Firefox < 110.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

debiandebian/firefox< firefox 110.0-1 (sid)
CVEListV5mozilla/firefoxunspecified110
NVDmozilla/firefox< 110.0
Ubuntumozilla/firefox< 110.0+build3-0ubuntu0.18.04.1+3
mozillamozilla/firefox

🔴Vulnerability Details

4
GHSA
GHSA-77mp-cm2p-44gj: When dragging and dropping an image cross-origin, the image's size could potentially be leaked2023-06-02
OSV
firefox regressions2023-03-01
OSV
firefox vulnerabilities2023-02-20
OSV
CVE-2023-25741: When dragging and dropping an image cross-origin, the image's size could potentially be leaked2023-02-15

📋Vendor Advisories

5
Ubuntu
Firefox regressions2023-03-01
Ubuntu
Firefox vulnerabilities2023-02-20
Red Hat
Mozilla: Same-origin policy leak via image drag and drop2023-02-14
Debian
CVE-2023-25741: firefox - When dragging and dropping an image cross-origin, the image's size could potenti...2023
Mozilla
Mozilla Foundation Security Advisory 2023-05: CVE-2023-25741