VulnerabilityModified
CVE-2023-25741
When dragging and dropping an image cross-origin, the image's size could potentially be leaked.
MEDIUM 6.5EPSS 0.77%
Does this matter?
Lower severity and a low EPSS score (0.77%). Track it; it rarely justifies an emergency change on its own.
Description
When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until further review. This vulnerability affects Firefox < 110.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 0.77% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- mozilla/firefox
- Source
- security@mozilla.org
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1437126Issue Tracking, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1812611Exploit, Issue Tracking, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1813376Issue Tracking, Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2023-05/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1437126Issue Tracking, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1812611Exploit, Issue Tracking, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1813376Issue Tracking, Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2023-05/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.