LOW
Persisted search terms were formatted as URLs
Published Sep 11, 2023
3.1
LOWCVSS 3.1
EPSS 0.45%
Description
Search queries in the default search engine could appear to have been the currently navigated URL if the search query itself was a well formed URL. This could have led to a site spoofing another if it had been maliciously set as the default search engine. This vulnerability affects Firefox < 117.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<117
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (3)
- https://bugzilla.mozilla.org/show_bug.cgi?id=1842766 Issue TrackingPermissions Required
- https://security.gentoo.org/glsa/202401-10
- https://www.mozilla.org/security/advisories/mfsa2023-34/ Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=1842766 | Issue TrackingPermissions Required | |
| https://security.gentoo.org/glsa/202401-10 | ||
| https://www.mozilla.org/security/advisories/mfsa2023-34/ | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Sep 11, 2023
Updated Dec 18, 2025
Reserved Aug 29, 2023
Link CVE-2023-4579
CISA Vulnrichment
Updated Oct 11, 2024