SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-4579

This could have led to a site spoofing another if it had been maliciously set as the default search engine.

LOW 3.1EPSS 0.45%

Does this matter?

Lower severity and a low EPSS score (0.45%). Track it; it rarely justifies an emergency change on its own.

Description

Search queries in the default search engine could appear to have been the currently navigated URL if the search query itself was a well formed URL. This could have led to a site spoofing another if it had been maliciously set as the default search engine. This vulnerability affects Firefox < 117.

CVSS 3.1
3.1 LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS
0.45% probability · 38th percentile
CISA KEV
Not listed
Affected
mozilla/firefox
Source
security@mozilla.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.