Unrated severityNVD Advisory· Published Jun 24, 2021· Updated Aug 3, 2024
CVE-2021-23999
CVE-2021-23999
Description
If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
Affected products
38- osv-coords35 versionspkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweedpkg:rpm/suse/MozillaFirefox&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP2pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Manager%20Proxy%204.0pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.0pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Manager%20Server%204.0pkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP2
< 128.5.1-1.1+ 34 more
- (no CPE)range: < 128.5.1-1.1
- (no CPE)range: < 78.10.0-lp152.2.55.1
- (no CPE)range: < 92.0-1.2
- (no CPE)range: < 78.10.0-lp152.2.41.1
- (no CPE)range: < 91.1.1-1.1
- (no CPE)range: < 78.10.0-112.57.2
- (no CPE)range: < 78.10.0-3.139.1
- (no CPE)range: < 78.10.0-3.139.1
- (no CPE)range: < 78.10.0-3.139.1
- (no CPE)range: < 78.10.0-3.139.1
- (no CPE)range: < 78.10.0-3.139.1
- (no CPE)range: < 78.10.0-8.38.1
- (no CPE)range: < 78.10.0-78.126.1
- (no CPE)range: < 78.10.0-112.57.2
- (no CPE)range: < 78.10.0-112.57.2
- (no CPE)range: < 78.10.0-112.57.2
- (no CPE)range: < 78.10.0-112.57.2
- (no CPE)range: < 78.10.0-112.57.2
- (no CPE)range: < 78.10.0-3.139.1
- (no CPE)range: < 78.10.0-3.139.1
- (no CPE)range: < 78.10.0-3.139.1
- (no CPE)range: < 78.10.0-112.57.2
- (no CPE)range: < 78.10.0-112.57.2
- (no CPE)range: < 78.10.0-112.57.2
- (no CPE)range: < 78.10.0-3.139.1
- (no CPE)range: < 78.10.0-3.139.1
- (no CPE)range: < 78.10.0-112.57.2
- (no CPE)range: < 78.10.0-3.139.1
- (no CPE)range: < 78.10.0-3.139.1
- (no CPE)range: < 78.10.0-3.139.1
- (no CPE)range: < 78.10.0-112.57.2
- (no CPE)range: < 78.10.0-112.57.2
- (no CPE)range: < 78.10.0-112.57.2
- (no CPE)range: < 78.10.0-112.57.2
- (no CPE)range: < 78.10.0-8.23.1
- Range: unspecified
- Range: unspecified
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- bugzilla.mozilla.org/show_bug.cgimitrex_refsource_MISC
- www.mozilla.org/security/advisories/mfsa2021-14/mitrex_refsource_MISC
- www.mozilla.org/security/advisories/mfsa2021-15/mitrex_refsource_MISC
- www.mozilla.org/security/advisories/mfsa2021-16/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.