PT-2023-6529 · Mozilla+5 · Firefox+5

Annevk

·

Publicado

2023-10-24

·

Atualizado

2025-03-14

·

CVE-2023-5722

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 119
Description The issue is related to insufficient protection of service data when processing the Vary header response for matching request headers. An attacker can exploit this by sending iterative requests to learn the size of an opaque response and the contents of a server-supplied Vary header, potentially allowing unauthorized access to protected information.
Recommendations For versions prior to 119, update to Firefox version 119 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information until the update is applied.

Exploit

Correção

Information Disclosure

Side Channel Attack

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-6639
ALT-PU-2023-7363
ALT-PU-2023-7774
ALT-PU-2024-13898
ALT-PU-2024-15839
ALT-PU-2024-15840
BDU:2023-07276
CVE-2023-5722
OESA-2025-1265
OESA-2025-1268
OPENSUSE-SU-2023_4214-1
OPENSUSE-SU-2024:13385-1
OPENSUSE-SU-2024:14572-1
SUSE-SU-2023:4212-1
SUSE-SU-2023:4213-1
SUSE-SU-2023:4214-1
USN-6456-1
USN-6456-2

Produtos afetados

Alt Linux
Astra Linux
Firefox
Linuxmint
Suse
Ubuntu