PT-2023-3105 · Mozilla+4 · Firefox+4

Jun Kokatsu

·

Publicado

2023-06-06

·

Atualizado

2025-03-14

·

CVE-2023-34415

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 114
Description The issue is related to how Firefox handles site-isolated processes for documents loaded from data: URLs that result from redirects. Previously, Firefox would load such documents in the same process as the site that issued the redirect, bypassing site-isolation protections against Spectre-like attacks on sites hosting an "open redirect". Firefox has been updated to no longer follow HTTP redirects to data: URLs, addressing this issue. The vulnerability can be exploited by a remote attacker to bypass security restrictions and redirect a user to an arbitrary URL.
Recommendations For versions prior to 114, update to Firefox version 114 or later to resolve the issue.

Exploit

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-1974
ALT-PU-2023-5754
ALT-PU-2023-6436
ALT-PU-2024-14035
ALT-PU-2024-3614
ALT-PU-2024-4241
BDU:2023-03197
CVE-2023-34415
OESA-2025-1265
OESA-2025-1268
OPENSUSE-SU-2024:12991-1
OPENSUSE-SU-2024:14572-1
USN-6143-1
USN-6143-2
USN-6143-3

Produtos afetados

Alt Linux
Astra Linux
Firefox
Linuxmint
Ubuntu