CVE-2023-34414Improper Certificate Validation in Mozilla Firefox

Severity
3.1LOWNVD
EPSS
0.1%
top 80.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 19
Latest updateAug 26

Description

The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts and permission dialogs from attacks that exploit human response time delays. If a malicious page elicited user clicks in precise locations immediately before navigating to a site with a certificate error and made the renderer extremely busy at the same time, it could create a gap between when the error page was loaded and when the display actually refreshed. With the right timi

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:LExploitability: 1.6 | Impact: 1.4

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified114
NVDmozilla/firefox< 114.0
CVEListV5mozilla/firefox_esrunspecified102.12
NVDmozilla/firefox_esr< 102.12
Ubuntumozilla/firefox< 114.0+build3-0ubuntu0.20.04.1+1

🔴Vulnerability Details

7
OSV
thunderbird vulnerabilities2023-07-11
OSV
firefox regressions2023-06-21
GHSA
GHSA-75j9-5hgg-gprr: The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts and permission dialogs from at2023-06-19
OSV
CVE-2023-34414: The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts and permission dialogs from at2023-06-19
CVEList
CVE-2023-34414: The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts and permission dialogs from at2023-06-19

📋Vendor Advisories

7
Ubuntu
Thunderbird vulnerabilities2023-07-11
Ubuntu
Firefox vulnerabilities2023-06-07
Red Hat
Mozilla: Click-jacking certificate exceptions through rendering lag2023-06-06
Debian
CVE-2023-34414: firefox - The error page for sites with invalid TLS certificates was missing the activatio...2023
Mozilla
Mozilla Foundation Security Advisory 2023-19: CVE-2023-34414

💬Community

1
Bugzilla
HTTPS-Only mode bypass through clickjacking2023-08-26
CVE-2023-34414 — Improper Certificate Validation | cvebase