CVE Database
/

CVE-2023-34415

Back to search

CVE-2023-34415

Published: Jun 19, 2023

Modified: Feb 13, 2025

PUBLISHED

Description

When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that document in the same process as the site that issued the redirect. This bypassed the site-isolation protections against Spectre-like attacks on sites that host an "open redirect". Firefox no longer follows HTTP redirects to data: URLs. This vulnerability affects Firefox < 114.

VendorProductVersions

Mozilla

Firefox

affected
unspecified - < 114

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now