Regular expressions used to filter out forbidden properties and values from style directives in calls to <code>console.log</code> weren't accounting for external URLs. Data could then be potentially exfiltrated from the browser. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7.
2023-06-02T17:15:10.823
2025-01-10T18:15:16.460
Modified
CVSSv3.1: 6.5 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mozilla | firefox | < 109.0 | Yes |
| Application | mozilla | firefox_esr | < 102.7 | Yes |
| Application | mozilla | thunderbird | < 102.7 | Yes |