CVE-2023-6209

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
21/11/2023
Last modified:
30/11/2023

Description

Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 120.0 (excluding)
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* 115.5.0 (excluding)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* 115.5 (excluding)
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*