PT-2021-7945 · Mozilla+4 · Firefox For Android+6
Zoracon
·
Published
2021-01-06
·
Updated
2025-03-14
·
CVE-2023-29538
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 112
Firefox for Android versions prior to 112
Focus for Android versions prior to 112
Description
A vulnerability in the WebExtension component of the Firefox browser is related to the disclosure of information in an error data area. Under specific circumstances, a WebExtension may have received a
jar:file:/// URI instead of a moz-extension:/// URI during a load request, leaking directory paths on the user's machine.Recommendations
For Firefox versions prior to 112, update to version 112 or later.
For Firefox for Android versions prior to 112, update to version 112 or later.
For Focus for Android versions prior to 112, update to version 112 or later.
Exploit
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Firefox
Firefox For Android
Focus For Android
Linuxmint
Ubuntu