cve/2023/CVE-2023-6209.md
2024-06-07 17:53:02 +00:00

22 lines
1.2 KiB
Markdown

### [CVE-2023-6209](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6209)
![](https://img.shields.io/static/v1?label=Product&message=Firefox%20ESR&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Firefox&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Thunderbird&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=unspecified%3C%20115.5%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=unspecified%3C%20115.5.0%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=unspecified%3C%20120%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Incorrect%20parsing%20of%20relative%20URLs%20starting%20with%20%22%2F%2F%2F%22&color=brighgreen)
### Description
Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
### POC
#### Reference
- https://bugzilla.mozilla.org/show_bug.cgi?id=1858570
#### Github
- https://github.com/punggawacybersecurity/CVE-List