CVE-2023-5725
CVE-2023-5725
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 0.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
24 oct 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://bugzilla.mozilla.org/show_bug.cgi?id=1845739https://lists.debian.org/debian-lts-announce/2023/10/msg00037.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00042.htmlhttps://www.debian.org/security/2023/dsa-5535https://www.debian.org/security/2023/dsa-5538https://www.mozilla.org/security/advisories/mfsa2023-45/https://www.mozilla.org/security/advisories/mfsa2023-46/https://www.mozilla.org/security/advisories/mfsa2023-47/