CVE-2023-23601
Summary
| CVE | CVE-2023-23601 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-02 17:15:00 UTC |
| Updated | 2023-06-08 18:55:00 UTC |
| Description | Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160420 Oracle Enterprise Linux Security Update for firefox (ELSA-2023-0296)
- 160425 Oracle Enterprise Linux Security Update for firefox (ELSA-2023-0288)
- 160432 Oracle Enterprise Linux Security Update for firefox (ELSA-2023-0285)
- 160434 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2023-0456)
- 160435 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2023-0463)
- 160438 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2023-0476)
- 181483 Debian Security Update for firefox-esr (DSA 5322-1)
- 181485 Debian Security Update for firefox-esr (DLA 3275-1)
- 181589 Debian Security Update for thunderbird (CVE-2023-23601)
- 181592 Debian Security Update for thunderbird (DLA 3324-1)
- 181680 Debian Security Update for thunderbird (DSA 5355-1)
- 199122 Ubuntu Security Notification for Firefox Vulnerabilities (USN-5816-1)
- 199147 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5824-1)
- 241084 Red Hat Update for firefox (RHSA-2023:0295)
- 241087 Red Hat Update for firefox (RHSA-2023:0285)
- 241089 Red Hat Update for firefox (RHSA-2023:0296)
- 241090 Red Hat Update for firefox (RHSA-2023:0286)
- 241092 Red Hat Update for firefox (RHSA-2023:0288)
- 241094 Red Hat Update for firefox (RHSA-2023:0289)
- 241133 Red Hat Update for thunderbird (RHSA-2023:0461)
- 241134 Red Hat Update for thunderbird (RHSA-2023:0463)
- 241136 Red Hat Update for thunderbird (RHSA-2023:0460)
- 241137 Red Hat Update for thunderbird (RHSA-2023:0462)
- 241139 Red Hat Update for thunderbird (RHSA-2023:0456)
- 241141 Red Hat Update for thunderbird (RHSA-2023:0476)
- 241634 Red Hat Update for thunderbird (RHSA-2023:0457)
- 241651 Red Hat Update for firefox (RHSA-2023:0290)
- 241671 Red Hat Update for firefox (RHSA-2023:0294)
- 241680 Red Hat Update for thunderbird (RHSA-2023:0459)
- 257208 CentOS Security Update for firefox (CESA-2023:0296)
- 257209 CentOS Security Update for thunderbird (CESA-2023:0456)
- 354760 Amazon Linux Security Advisory for thunderbird : ALAS2-2023-1951
- 356198 Amazon Linux Security Advisory for firefox : ALASFIREFOX-2023-013
- 377905 Mozilla Firefox Multiple Vulnerabilities (MFSA2023-01)
- 377906 Mozilla Firefox ESR Multiple Vulnerabilities (MFSA2023-02)
- 377924 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2023-03)
- 503454 Alpine Linux Security Update for firefox-esr
- 506062 Alpine Linux Security Update for firefox-esr
- 710713 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 202305-06)
- 710715 Gentoo Linux Mozilla Thunderbird Multiple Vulnerabilities (GLSA 202305-13)
- 753546 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2023:0113-1)
- 753552 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2023:0112-1)
- 753553 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2023:0111-1)
- 753663 SUSE Enterprise Linux Security Update for MozillaThunderbird (SUSE-SU-2023:0329-1)
- 940890 AlmaLinux Security Update for firefox (ALSA-2023:0288)
- 940893 AlmaLinux Security Update for firefox (ALSA-2023:0285)
- 940912 AlmaLinux Security Update for thunderbird (ALSA-2023:0463)
- 940916 AlmaLinux Security Update for thunderbird (ALSA-2023:0476)
- 960478 Rocky Linux Security Update for thunderbird (RLSA-2023:0476)
- 960574 Rocky Linux Security Update for thunderbird (RLSA-2023:0463)
- 960620 Rocky Linux Security Update for firefox (RLSA-2023:0288)
- 960644 Rocky Linux Security Update for firefox (RLSA-2023:0285)