CVE-2024-0748Open Redirect in Mozilla Firefox

CWE-601Open Redirect11 documents8 sources
Severity
4.3MEDIUMNVD
OSV6.5
EPSS
0.2%
top 56.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 23
Latest updateFeb 7

Description

A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar or history. This vulnerability affects Firefox < 122.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

CVEListV5mozilla/firefoxunspecified122
NVDmozilla/firefox< 122.0
Ubuntumozilla/firefox< 122.0+build2-0ubuntu0.20.04.1+1

🔴Vulnerability Details

5
OSV
firefox regressions2024-02-07
OSV
firefox vulnerabilities2024-01-29
GHSA
GHSA-x73f-6qwm-hh3x: A compromised content process could have updated the document URI2024-01-23
OSV
CVE-2024-0748: A compromised content process could have updated the document URI2024-01-23
CVEList
CVE-2024-0748: A compromised content process could have updated the document URI2024-01-23

📋Vendor Advisories

5
Ubuntu
Firefox regressions2024-02-07
Ubuntu
Firefox vulnerabilities2024-01-29
Red Hat
firefox: an arbitrary URI in the address bar or history2024-01-23
Debian
CVE-2024-0748: firefox - A compromised content process could have updated the document URI. This could ha...2024
Mozilla
Mozilla Foundation Security Advisory 2024-01: CVE-2024-0748
CVE-2024-0748 — Open Redirect in Mozilla Firefox | cvebase