发布时间: 2023年9月22日
修改时间: 2024年10月31日
A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
NVD | openEuler | |
---|---|---|
Confidentiality | Low | Low |
Attack Vector | Network | Network |
CVSS评分 | 6.1 | 6.1 |
Attack Complexity | Low | Low |
Privileges Required | None | None |
Scope | Changed | Changed |
Integrity | Low | Low |
User Interaction | Required | Required |
Availability | None | None |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2023-1895 | firefox security update | 2023年9月22日 |
KylinSec-SA-2023-1982 | firefox security update | 2023年9月22日 |
KylinSec-SA-2023-2275 | firefox security update | 2023年9月22日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | firefox | Fixed |
KY3.5.1 | firefox | Fixed |
KY3.5.2 | firefox | Fixed |