Cross-site scripting in Mozilla Firefox - CVE-2017-7823
Published: September 28, 2017 / Updated: September 29, 2017
Vulnerability identifier: #VU8629
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2017-7823
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform XSS attacks.
The content security policy (CSP)
The content security policy (CSP)
sandbox directive did not create a unique origin for the document, causing it to behave as if the allow-same-origin keyword were always specified. This could allow a Cross-Site Scripting (XSS) attack to be launched from unsafe content. Affected software
Mozilla Firefox
Firefox ESR
Gentoo Linux
Arch Linux
Debian Linux
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
SUSE Linux
Ubuntu
Mozilla Thunderbird
Firefox ESR
Gentoo Linux
Arch Linux
Debian Linux
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
SUSE Linux
Ubuntu
Mozilla Thunderbird
How to mitigate CVE-2017-7823
Update to version 56.0.
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox
- Multiple vulnerabilities in Firefox ESR
- Debian update for firefox-esr
- Ubuntu update for Firefox
- Ubuntu update for Firefox
- Ubuntu update for Thunderbird
- Arch Linux update for thunderbird
- Multiple vulnerabilities in Mozilla Thunderbird
- Ubuntu update for Firefox
- Debian update for thunderbird
- SUSE Linux update for MozillaFirefox
- Gentoo update for Mozilla Firefox
- SUSE Linux update for MozillaFirefox
- OpenSUSE Linux update for MozillaThunderbird
- OpenSUSE Linux update for MozillaThunderbird
- SUSE Linux update for MozillaFirefox
- OpenSUSE Linux update for Mozilla Firefox and NSS
- Gentoo update for Mozilla Thunderbird
- Red Hat update for thunderbird
- Red Hat update for firefox