CVE-2023-4583Improper Check for Unusual or Exceptional Conditions in Mozilla Firefox

Severity
7.5HIGHNVD
OSV8.8OSV6.5
EPSS
0.1%
top 65.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 11
Latest updateOct 3

Description

When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private session had ended. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified117
NVDmozilla/firefox< 117.0
CVEListV5mozilla/firefox_esrunspecified115.2
NVDmozilla/firefox_esr< 115.2
Ubuntumozilla/firefox< 117.0+build2-0ubuntu0.20.04.1

🔴Vulnerability Details

5
OSV
thunderbird vulnerabilities2023-10-03
GHSA
GHSA-wxxp-w379-49qj: When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already2023-09-11
CVEList
Browsing Context potentially not cleared when closing Private Window2023-09-11
OSV
CVE-2023-4583: When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already2023-09-11
OSV
firefox vulnerabilities2023-08-30

📋Vendor Advisories

8
Ubuntu
Thunderbird vulnerabilities2023-10-03
Microsoft
When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been discarded which was not always the case for 2023-09-12
Ubuntu
Firefox vulnerabilities2023-08-30
Red Hat
Mozilla: Browsing Context potentially not cleared when closing Private Window2023-08-29
Debian
CVE-2023-4583: firefox - When checking if the Browsing Context had been discarded in `HttpBaseChannel`, i...2023
CVE-2023-4583 — Mozilla Firefox vulnerability | cvebase