CVE-2023-4579Mozilla Firefox vulnerability

8 documents7 sources
Severity
3.1LOWNVD
OSV6.5
EPSS
0.2%
top 62.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 11

Description

Search queries in the default search engine could appear to have been the currently navigated URL if the search query itself was a well formed URL. This could have led to a site spoofing another if it had been maliciously set as the default search engine. This vulnerability affects Firefox < 117.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 1.6 | Impact: 1.4

Affected Packages3 packages

CVEListV5mozilla/firefoxunspecified117
NVDmozilla/firefox< 117.0
Ubuntumozilla/firefox< 117.0+build2-0ubuntu0.20.04.1

🔴Vulnerability Details

4
CVEList
Persisted search terms were formatted as URLs2023-09-11
GHSA
GHSA-qj3f-v6p7-vxvm: Search queries in the default search engine could appear to have been the currently navigated URL if the search query itself was a well formed URL2023-09-11
OSV
firefox vulnerabilities2023-08-30
OSV
CVE-2023-4579: Search queries in the default search engine could appear to have been the currently navigated URL if the search query itself was a well formed URL2023-08-30

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2023-08-30
Debian
CVE-2023-4579: firefox - Search queries in the default search engine could appear to have been the curren...2023
Mozilla
Mozilla Foundation Security Advisory 2023-34: CVE-2023-4579
CVE-2023-4579 — Mozilla Firefox vulnerability | cvebase