PT-2023-2864 · Mozilla+4 · Firefox Esr+5

Anne Van Kesteren

·

Published

2023-05-09

·

Updated

2025-03-14

·

CVE-2023-32208

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 113 Firefox ESR (affected versions not specified)
Description The issue is related to a lack of protection for service worker data, which could allow a remote attacker to disclose protected information through the use of dynamic import(). This affects Firefox and Firefox ESR browsers.
Recommendations For Firefox versions prior to 113, update to version 113 or later to resolve the issue. For Firefox ESR, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1773
ALT-PU-2023-5754
ALT-PU-2023-6436
ALT-PU-2024-14035
ALT-PU-2024-3614
ALT-PU-2024-4241
BDU:2023-02811
CVE-2023-32208
OESA-2025-1265
OESA-2025-1268
OPENSUSE-SU-2024:12920-1
OPENSUSE-SU-2024:14572-1
USN-6074-1
USN-6074-2
USN-6074-3

Affected Products

Alt Linux
Astra Linux
Firefox
Firefox Esr
Linuxmint
Ubuntu