CVE-2023-4051Authentication Bypass by Spoofing in Mozilla Firefox

Severity
7.5HIGHNVD
OSV5.3
EPSS
0.1%
top 65.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 1
Latest updateAug 29

Description

A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages6 packages

CVEListV5mozilla/firefoxunspecified116
NVDmozilla/firefox< 116.0
CVEListV5mozilla/firefox_esrunspecified115.2
Ubuntumozilla/firefox< 116.0+build2-0ubuntu0.20.04.2
CVEListV5mozilla/thunderbirdunspecified115.2

🔴Vulnerability Details

6
OSV
firefox regressions2023-08-21
OSV
firefox regressions2023-08-08
OSV
firefox vulnerabilities2023-08-02
OSV
CVE-2023-4051: A website could have obscured the full screen notification by using the file open dialog2023-08-01
CVEList
Full screen notification obscured by file open dialog2023-08-01

📋Vendor Advisories

6
Red Hat
Mozilla: Full screen notification obscured by file open dialog2023-08-29
Ubuntu
Firefox vulnerabilities2023-08-02
Debian
CVE-2023-4051: firefox - A website could have obscured the full screen notification by using the file ope...2023
Mozilla
Mozilla Foundation Security Advisory 2023-38: CVE-2023-4051
Mozilla
Mozilla Foundation Security Advisory 2023-36: CVE-2023-4051
CVE-2023-4051 — Authentication Bypass by Spoofing | cvebase