When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private session had ended. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
History

Thu, 19 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-754
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2023-09-11T08:02:01.933Z

Updated: 2024-09-19T19:57:57.681Z

Reserved: 2023-08-29T03:37:00.389Z

Link: CVE-2023-4583

cve-icon Vulnrichment

Updated: 2024-08-02T07:31:06.553Z

cve-icon NVD

Status : Modified

Published: 2023-09-11T09:15:09.680

Modified: 2024-11-21T08:35:28.857

Link: CVE-2023-4583

cve-icon Redhat

Severity : Low

Publid Date: 2023-08-29T00:00:00Z

Links: CVE-2023-4583 - Bugzilla