In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties.
*This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121.
*This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2025-02-13T17:26:40.464Z
Reserved: 2023-12-15T17:42:57.290Z
Link: CVE-2023-6868
No data.
Status : Modified
Published: 2023-12-19T14:15:07.983
Modified: 2024-11-21T08:44:43.493
Link: CVE-2023-6868
No data.
OpenCVE Enrichment
No data.
Weaknesses