A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `DOMParser::ParseFromSafeString`. This could have lead to bypassing web security checks. This vulnerability affects Firefox < 109.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | gentoo-linux-upgrade-www-client-firefoxgentoo-linux-upgrade-www-client-firefox-bin | May 4, 2023 | May 3, 2023 | |
| Mfsa2023 01 | mozilla-firefox-upgrade-109_0 | Jan 18, 2023 | Jan 17, 2023 | |
| Ubuntu | ubuntu-upgrade-firefox | Jan 23, 2023 | Jan 23, 2023 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Jun 2, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub