When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would have resolved those in the context of the current user. <br>*This bug only affects Firefox on Windows. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefoxUpgrade thunderbirdUpgrade firefox-esr | Aug 22, 2024 | Jun 2, 2023 |
| Amazon Linux Ami 2 | — | Upgrade firefoxUpgrade thunderbirdUpgrade firefox-debuginfoUpgrade thunderbird-debuginfo | Mar 22, 2023 | Mar 22, 2023 |
| Gentoo Linux | — | Upgrade www-client/firefox.Upgrade mail-client/thunderbird.Upgrade mail-client/thunderbird-bin.Upgrade www-client/firefox-bin. | May 31, 2023 | May 30, 2023 |
| Mfsa2023 09 | — | Upgrade to Mozilla Firefox version 111.0Upgrade to the latest version of Mozilla Firefox | Mar 15, 2023 | Mar 14, 2023 |
| Mfsa2023 10 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 102.9 | Mar 15, 2023 | Mar 14, 2023 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 102.9Upgrade to the latest version of Mozilla Thunderbird | Mar 16, 2023 | Mar 14, 2023 |
| Suse | — | Upgrade mozillafirefox-branding-upstreamUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefoxUpgrade MozillaFirefox-develUpgrade MozillaThunderbirdUpgrade MozillaThunderbird-translations-commonUpgrade MozillaThunderbird-translations-other | Mar 15, 2023 | Mar 14, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 2, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub