CVE-2023-6871: Medium severity firefox vulnerability
Published Dec 19, 2023
·Updated
Last updated 24 July 2024
Other sources
Under certain conditions, Firefox did not display a warning when a user attempted to navigate to a new protocol handler.
— Mozilla
Affected Software
3 affected componentsFixes available
Mozilla Firefox<121
121
Mozilla Firefox<121.0
debian/firefox
138.0.1-1
Event History
Dec 19, 2023
CVE Published
via Mozilla·12:00 AM
CVE Published
via MITRE·01:38 PM
Data Sourced
via MITRE·01:38 PM
DescriptionWeakness
Jan 12, 2024
Data Sourced
via Launchpad·12:29 AM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·04:19 AM
RemedyDescriptionSeverityAffected Software
Apr 4, 2025
Data Sourced
via Debian·04:33 AM
DescriptionAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2023-6871?
CVE-2023-6871 is of moderate severity due to insufficient warning when navigating to new protocol handlers in Firefox.
2
How do I fix CVE-2023-6871?
To fix CVE-2023-6871, update Firefox to version 134.0.2-2 or later.
3
Which versions of Firefox are affected by CVE-2023-6871?
CVE-2023-6871 affects Firefox versions up to 121.0.
4
Is CVE-2023-6871 exploitable by users?
Yes, CVE-2023-6871 can be exploited by users if they attempt to navigate to untrusted protocol handlers.
5
What impact does CVE-2023-6871 have on Firefox users?
CVE-2023-6871 could lead users to inadvertently access dangerous or malicious sites without warnings.