PT-2023-3105 · Mozilla+4 · Firefox+4

Jun Kokatsu

·

Published

2023-06-06

·

Updated

2025-03-14

·

CVE-2023-34415

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 114
Description The issue is related to how Firefox handles site-isolated processes for documents loaded from data: URLs that result from redirects. Previously, Firefox would load such documents in the same process as the site that issued the redirect, bypassing site-isolation protections against Spectre-like attacks on sites hosting an "open redirect". Firefox has been updated to no longer follow HTTP redirects to data: URLs, addressing this issue. The vulnerability can be exploited by a remote attacker to bypass security restrictions and redirect a user to an arbitrary URL.
Recommendations For versions prior to 114, update to Firefox version 114 or later to resolve the issue.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1974
ALT-PU-2023-5754
ALT-PU-2023-6436
ALT-PU-2024-14035
ALT-PU-2024-3614
ALT-PU-2024-4241
BDU:2023-03197
CVE-2023-34415
OESA-2025-1265
OESA-2025-1268
OPENSUSE-SU-2024:12991-1
OPENSUSE-SU-2024:14572-1
USN-6143-1
USN-6143-2
USN-6143-3

Affected Products

Alt Linux
Astra Linux
Firefox
Linuxmint
Ubuntu