Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-6867


The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.


Published

2023-12-19T14:15:07.933

Last Modified

2024-11-21T08:44:43.367

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-1021

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mozilla firefox < 121.0 Yes
Application mozilla firefox_esr < 115.6 Yes
Operating System debian debian_linux 10.0 Yes
Operating System debian debian_linux 11.0 Yes
Operating System debian debian_linux 12.0 Yes

References