CVE-2023-32210
Last modified
CVE-2023-32210 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Documents were incorrectly assuming an ordering of principal objects when ensuring we were loading an appropriately privileged principal. In certain circumstances it might have been possible to cause a document to be loaded with a higher privileged principal than intended. EPSS estimates a 0.54% chance of exploitation in the next 30 days.
Description
Documents were incorrectly assuming an ordering of principal objects when ensuring we were loading an appropriately privileged principal. In certain circumstances it might have been possible to cause a document to be loaded with a higher privileged principal than intended. This vulnerability affects Firefox < 113.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 113.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1776755Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2023-16/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1776755Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2023-16/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-32210?
How severe is CVE-2023-32210?
How do I fix CVE-2023-32210?
Are you affected by CVE-2023-32210?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
