CVE-2023-4053 — Link Following in Mozilla Firefox
Severity
6.5MEDIUMNVD
OSV5.3
EPSS
0.1%
top 65.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 1
Latest updateAug 29
Description
A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages6 packages
🔴Vulnerability Details
6OSV▶
CVE-2023-4053: A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL↗2023-08-01
GHSA▶
GHSA-8mxh-558j-w4gm: A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL↗2023-08-01
📋Vendor Advisories
6Debian▶
CVE-2023-4053: firefox - A website could have obscured the full screen notification by using a URL with a...↗2023