CVE-2023-6867UI Misrepresentation / Clickjacking in Mozilla Firefox

Severity
6.1MEDIUMNVD
OSV4.3
EPSS
0.9%
top 23.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 19
Latest updateJan 11

Description

The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages5 packages

CVEListV5mozilla/firefoxunspecified121
NVDmozilla/firefox< 121.0
CVEListV5mozilla/firefox_esrunspecified115.6
NVDmozilla/firefox_esr< 115.6
Ubuntumozilla/firefox< 121.0+build1-0ubuntu0.20.04.1

Also affects: Debian Linux 10.0, 11.0, 12.0

🔴Vulnerability Details

5
OSV
firefox regressions2024-01-11
OSV
firefox vulnerabilities2024-01-02
OSV
CVE-2023-6867: The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts2023-12-19
CVEList
CVE-2023-6867: The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts2023-12-19
GHSA
GHSA-2mpv-2j92-5mm4: The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts2023-12-19

📋Vendor Advisories

5
Ubuntu
Firefox vulnerabilities2024-01-02
Red Hat
Mozilla: Clickjacking permission prompts using the popup transition2023-12-19
Debian
CVE-2023-6867: firefox - The timing of a button click causing a popup to disappear was approximately the ...2023
Mozilla
Mozilla Foundation Security Advisory 2023-54: CVE-2023-6867
Mozilla
Mozilla Foundation Security Advisory 2023-56: CVE-2023-6867
CVE-2023-6867 — UI Misrepresentation / Clickjacking | cvebase