Back to search
CVE-2023-34415
Published: Jun 19, 2023
Modified: Feb 13, 2025
PUBLISHED
Description
When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that document in the same process as the site that issued the redirect. This bypassed the site-isolation protections against Spectre-like attacks on sites that host an "open redirect". Firefox no longer follows HTTP redirects to data: URLs. This vulnerability affects Firefox < 114.
| Vendor | Product | Versions |
|---|---|---|
Mozilla | Firefox | affected unspecified - < 114 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now