cbcvebase.
CVE-2023-6209
published 2023-11-21

CVE-2023-6209: Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host…

medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

Affected

21 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianfirefox< firefox 120.0-1 (sid)firefox 120.0-1 (sid)
debianfirefox-esr< firefox 120.0-1 (sid)firefox 120.0-1 (sid)
debianthunderbird< firefox 120.0-1 (sid)firefox 120.0-1 (sid)
mozillafirefox< 120.0120.0
mozillafirefox
mozillafirefox>= 0 < 120.0+build2-0ubuntu0.20.04.1120.0+build2-0ubuntu0.20.04.1
mozillafirefox>= 0 < 120.0.1+build1-0ubuntu0.20.04.1120.0.1+build1-0ubuntu0.20.04.1
mozillafirefox>= unspecified < 120120
mozillafirefox_esr< 115.5.0115.5.0
mozillafirefox_esr>= unspecified < 115.5.0115.5.0
mozillathunderbird< 115.5115.5
mozillathunderbird>= 0 < 1:115.5.0-1~deb11u11:115.5.0-1~deb11u1
mozillathunderbird>= 0 < 1:115.5.0-1~deb12u11:115.5.0-1~deb12u1
mozillathunderbird>= 0 < 1:115.5.0-11:115.5.0-1
mozillathunderbird>= 0 < 1:115.5.0-11:115.5.0-1
mozillathunderbird>= 0 < 1:115.5.0+build1-0ubuntu0.20.04.11:115.5.0+build1-0ubuntu0.20.04.1
mozillathunderbird>= 0 < 1:115.5.0+build1-0ubuntu0.22.04.11:115.5.0+build1-0ubuntu0.22.04.1
mozillathunderbird>= unspecified < 115.5115.5

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
osv6.5MEDIUM