Skip to main content

CVE-2023-23604

Severity Medium
Score 6.5/10

Summary

A duplicate "<code>SystemPrincipal</code>" object could be created when parsing a non-system html document via "<code>DOMParser::ParseFromSafeString</code>". This could have lead to bypassing web security checks. This vulnerability affects Firefox versions prior to 109.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • REQUIRED
  • NONE
  • NONE
  • NONE

Advisory Timeline

  • Published