Vulnerability identifier: #VU61109
Vulnerability risk: Low
CVSSv3.1:
CVE-ID:
CWE-ID:
CWE-284
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Firefox ESR
Client/Desktop applications /
Web browsers
Vendor: Mozilla
Description
The vulnerability allows a local user to gain access to victim's downloads.
The vulnerability exists due to browser stores files in the /tmp folder, which is accessible by all local users. A local user can read files from this folder and gain access to potentially sensitive information.
Note, the vulnerability affects Firefox ESR on macOS and Linux.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Firefox ESR: 91.0 - 91.6.1
CPE
External links
http://www.mozilla.org/en-US/security/advisories/mfsa2022-11/
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?