CVE-2023-4053Link Following in Mozilla Firefox

Severity
6.5MEDIUMNVD
OSV5.3
EPSS
0.1%
top 65.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 1
Latest updateAug 29

Description

A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

CVEListV5mozilla/firefoxunspecified116
NVDmozilla/firefox< 116.0
CVEListV5mozilla/firefox_esrunspecified115.2
Ubuntumozilla/firefox< 116.0+build2-0ubuntu0.20.04.2
CVEListV5mozilla/thunderbirdunspecified115.2

🔴Vulnerability Details

6
OSV
firefox regressions2023-08-21
OSV
firefox regressions2023-08-08
OSV
firefox vulnerabilities2023-08-02
OSV
CVE-2023-4053: A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL2023-08-01
GHSA
GHSA-8mxh-558j-w4gm: A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL2023-08-01

📋Vendor Advisories

6
Red Hat
Mozilla: Full screen notification obscured by external program2023-08-29
Ubuntu
Firefox vulnerabilities2023-08-02
Debian
CVE-2023-4053: firefox - A website could have obscured the full screen notification by using a URL with a...2023
Mozilla
Mozilla Foundation Security Advisory 2023-36: CVE-2023-4053
Mozilla
Mozilla Foundation Security Advisory 2023-38: CVE-2023-4053
CVE-2023-4053 — Link Following in Mozilla Firefox | cvebase