CVE-2023-29545
published 2023-06-19CVE-2023-29545: Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the…
PriorityP430medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.58%
44.5th percentile
Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the context of the current user.
*This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 112.0 | 112.0 |
| mozilla | firefox | — | — |
| mozilla | firefox_esr | < 102.10 | 102.10 |
| mozilla | thunderbird | < 102.10 | 102.10 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Windows Save As dialog resolved environment variables
vendor_redhat·2023-04-11·CVSS 6.5
CVE-2023-29545 [MEDIUM] CWE-428 Mozilla: Windows Save As dialog resolved environment variables
Mozilla: Windows Save As dialog resolved environment variables
Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the context of the current user.
*This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
The Mozilla Foundation Security Advisory describes this flaw as:
Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the context of the current user.
*This bug only affects Firefox on Windows. Other versions of Firefox are unaffected.*
S
Debian
CVE-2023-29545: firefox - Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested fil...
vendor_debian·2023·CVSS 6.5
CVE-2023-29545 [MEDIUM] CVE-2023-29545: firefox - Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested fil...
Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the context of the current user. *This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2023-15: CVE-2023-29545
vendor_mozilla·CVSS 6.5
CVE-2023-29545 [MEDIUM] Mozilla Foundation Security Advisory 2023-15: CVE-2023-29545
Mozilla Foundation Security Advisory 2023-15
CVE: CVE-2023-29545
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 102.10
Mozilla
Mozilla Foundation Security Advisory 2023-14: CVE-2023-29545
vendor_mozilla·CVSS 6.5
CVE-2023-29545 [MEDIUM] Mozilla Foundation Security Advisory 2023-14: CVE-2023-29545
Mozilla Foundation Security Advisory 2023-14
CVE: CVE-2023-29545
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 102.10
Mozilla
Mozilla Foundation Security Advisory 2023-13: CVE-2023-29545
vendor_mozilla·CVSS 6.5
CVE-2023-29545 [MEDIUM] Mozilla Foundation Security Advisory 2023-13: CVE-2023-29545
Mozilla Foundation Security Advisory 2023-13
CVE: CVE-2023-29545
Product: Firefox, Firefox for Android, Focus for Android
Impact: high
Fixed in: Firefox 112
Firefox for Android 112
Focus for Android 112
GHSA
GHSA-xhrg-vc2x-xrcj: Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those
ghsa_unreviewed·2023-06-19·CVSS 6.5
CVE-2023-29545 [MEDIUM] GHSA-xhrg-vc2x-xrcj: Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those
Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the context of the current user.
*This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
OSV
CVE-2023-29545: Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those
osv·2023-06-19·CVSS 6.5
CVE-2023-29545 [MEDIUM] CVE-2023-29545: Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those
Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the context of the current user. *This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1823077https://www.mozilla.org/security/advisories/mfsa2023-13/https://www.mozilla.org/security/advisories/mfsa2023-14/https://www.mozilla.org/security/advisories/mfsa2023-15/https://bugzilla.mozilla.org/show_bug.cgi?id=1823077https://www.mozilla.org/security/advisories/mfsa2023-13/https://www.mozilla.org/security/advisories/mfsa2023-14/https://www.mozilla.org/security/advisories/mfsa2023-15/
2023-06-19
Published