Mozilla · Thunderbird · CVE-2023-23603
**Name of the Vulnerable Software and Affected Versions**
Firefox versions prior to 109
Thunderbird versions prior to 102.7
Firefox ESR versions prior to 102.7
**Description**
The issue is related to insufficient processing of regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log`. This could potentially allow data exfiltration from the browser.
**Recommendations**
For Firefox versions prior to 109, update to version 109 or later.
For Thunderbird versions prior to 102.7, update to version 102.7 or later.
For Firefox ESR versions prior to 102.7, update to version 102.7 or later.