cvelist/2023/25xxx/CVE-2023-25731.json
2023-06-02 17:00:43 +00:00

68 lines
2.2 KiB
JSON

{
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2023-25731",
"ASSIGNER": "security@mozilla.org",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Mozilla",
"product": {
"product_data": [
{
"product_name": "Firefox",
"version": {
"version_data": [
{
"version_value": "110",
"version_affected": "<"
}
]
}
}
]
}
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Prototype pollution when rendering URLPreview"
}
]
}
]
},
"references": {
"reference_data": [
{
"url": "https://www.mozilla.org/security/advisories/mfsa2023-05/",
"refsource": "MISC",
"name": "https://www.mozilla.org/security/advisories/mfsa2023-05/"
},
{
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1801542",
"refsource": "MISC",
"name": "https://bugzilla.mozilla.org/show_bug.cgi?id=1801542"
}
]
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in privileged code. This vulnerability affects Firefox < 110."
}
]
}
}