CVE-2023-4055

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-4055
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-4055.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-4055
Related
Published
2023-08-01T16:15:09Z
Modified
2024-10-22T17:45:23.759978Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

When the number of cookies per domain was exceeded in document.cookie, the actual cookie jar sent to the host was no longer consistent with expected cookie jar state. This could have caused requests to be sent with some cookies missing. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

References

Affected packages

Debian:11 / firefox-esr

Package

Name
firefox-esr
Purl
pkg:deb/debian/firefox-esr?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
102.14.0esr-1~deb11u1

Affected versions

78.*

78.12.0esr-1
78.13.0esr-1~deb9u1
78.13.0esr-1~deb10u1
78.13.0esr-1~deb11u1
78.13.0esr-1
78.14.0esr-1~deb9u1
78.14.0esr-1~deb10u1
78.14.0esr-1~deb11u1
78.14.0esr-1
78.15.0esr-1~deb9u1
78.15.0esr-1~deb10u1
78.15.0esr-1~deb11u1

91.*

91.0esr-1
91.0.1esr-1
91.1.0esr-1
91.2.0esr-1
91.3.0esr-1
91.3.0esr-2
91.4.0esr-1
91.4.1esr-1~deb9u1
91.4.1esr-1~deb11u1
91.5.0esr-1~deb9u1
91.5.0esr-1~deb10u1
91.5.0esr-1~deb11u1
91.5.0esr-1
91.5.1esr-1
91.6.0esr-1~deb9u1
91.6.0esr-1~deb10u1
91.6.0esr-1~deb11u1
91.6.0esr-1
91.6.1esr-1~deb9u1
91.6.1esr-1~deb10u1
91.6.1esr-1~deb11u1
91.6.1esr-1
91.7.0esr-1~deb9u1
91.7.0esr-1~deb10u1
91.7.0esr-1~deb11u1
91.7.0esr-1
91.8.0esr-1~deb9u1
91.8.0esr-1~deb10u1
91.8.0esr-1~deb11u1
91.8.0esr-1
91.9.0esr-1~deb9u1
91.9.0esr-1~deb10u1
91.9.0esr-1~deb11u1
91.9.0esr-1
91.9.1esr-1~deb9u1
91.9.1esr-1~deb10u1
91.9.1esr-1~deb11u1
91.9.1esr-1
91.10.0esr-1~deb9u1
91.10.0esr-1~deb10u1
91.10.0esr-1~deb11u1
91.10.0esr-1
91.11.0esr-1~deb9u1
91.11.0esr-1~deb10u1
91.11.0esr-1~deb11u1
91.11.0esr-1
91.12.0esr-1~deb10u1
91.12.0esr-1~deb11u1
91.12.0esr-1
91.13.0esr-1~deb10u1
91.13.0esr-1~deb11u1

102.*

102.1.0esr-1
102.1.0esr-2
102.2.0esr-1
102.3.0esr-1~deb10u1
102.3.0esr-1~deb10u2
102.3.0esr-1~deb11u1
102.3.0esr-1
102.4.0esr-1~deb10u1
102.4.0esr-1~deb11u1
102.4.0esr-1
102.5.0esr-1~deb10u1
102.5.0esr-1~deb11u1
102.5.0esr-1
102.6.0esr-1~deb10u1
102.6.0esr-1~deb11u1
102.6.0esr-1
102.7.0esr-1~deb10u1
102.7.0esr-1~deb11u1
102.7.0esr-1
102.8.0esr-1~deb10u1
102.8.0esr-1~deb11u1
102.8.0esr-1
102.9.0esr-1~deb10u1
102.9.0esr-1~deb11u1
102.9.0esr-1
102.9.0esr-2
102.10.0esr-1~deb10u1
102.10.0esr-1~deb11u1
102.10.0esr-1
102.11.0esr-1~deb10u1
102.11.0esr-1~deb11u1
102.11.0esr-1
102.12.0esr-1~deb10u1
102.12.0esr-1~deb11u1
102.12.0esr-1~deb12u1
102.12.0esr-1
102.13.0esr-1~deb10u1
102.13.0esr-1~deb11u1
102.13.0esr-1~deb12u1
102.13.0esr-1
102.14.0esr-1~deb10u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / firefox-esr

Package

Name
firefox-esr
Purl
pkg:deb/debian/firefox-esr?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
102.14.0esr-1~deb12u1

Affected versions

102.*

102.11.0esr-1
102.12.0esr-1~deb10u1
102.12.0esr-1~deb11u1
102.12.0esr-1~deb12u1
102.12.0esr-1
102.13.0esr-1~deb10u1
102.13.0esr-1~deb11u1
102.13.0esr-1~deb12u1
102.13.0esr-1
102.14.0esr-1~deb10u1
102.14.0esr-1~deb11u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / firefox-esr

Package

Name
firefox-esr
Purl
pkg:deb/debian/firefox-esr?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
115.1.0esr-1

Affected versions

102.*

102.11.0esr-1
102.12.0esr-1~deb10u1
102.12.0esr-1~deb11u1
102.12.0esr-1~deb12u1
102.12.0esr-1
102.13.0esr-1~deb10u1
102.13.0esr-1~deb11u1
102.13.0esr-1~deb12u1
102.13.0esr-1
102.14.0esr-1~deb10u1
102.14.0esr-1~deb11u1
102.14.0esr-1~deb12u1
102.15.0esr-1~deb10u1
102.15.0esr-1~deb11u1
102.15.0esr-1~deb12u1
102.15.1esr-1~deb10u1
102.15.1esr-1~deb11u1
102.15.1esr-1~deb12u1

115.*

115.0.2esr-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:11 / thunderbird

Package

Name
thunderbird
Purl
pkg:deb/debian/thunderbird?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:102.14.0-1~deb11u1

Affected versions

1:78.*

1:78.12.0-1
1:78.13.0-1~deb9u1
1:78.13.0-1~deb10u1
1:78.13.0-1~deb11u1
1:78.13.0-1
1:78.14.0-1~deb9u1
1:78.14.0-1~deb10u1
1:78.14.0-1~deb11u1
1:78.14.0-1

1:84.*

1:84.0~b3-1

1:85.*

1:85.0~b3-1

1:86.*

1:86.0~b3-1

1:88.*

1:88.0~b2-1

1:89.*

1:89.0~b2-1

1:90.*

1:90.0~b2-1

1:91.*

1:91.0~b1-1
1:91.0~b3-1
1:91.0~b5-1
1:91.0-1
1:91.0.2-1
1:91.1.0-1
1:91.1.1-1
1:91.2.0-1
1:91.2.1-1
1:91.3.0-1
1:91.3.2-1
1:91.4.0-1
1:91.4.1-1~deb9u1
1:91.4.1-1~deb10u1
1:91.4.1-1~deb11u1
1:91.4.1-1
1:91.5.0-1~deb9u1
1:91.5.0-1
1:91.5.0-2~deb10u1
1:91.5.0-2~deb11u1
1:91.5.0-2
1:91.5.1-1
1:91.6.0-1~deb9u1
1:91.6.0-1~deb10u1
1:91.6.0-1~deb11u1
1:91.6.0-1
1:91.6.1-1~deb9u1
1:91.6.1-1~deb10u1
1:91.6.1-1~deb11u1
1:91.6.1-1
1:91.6.2-1~deb9u1
1:91.6.2-1~deb10u1
1:91.6.2-1~deb11u1
1:91.6.2-1
1:91.7.0-1
1:91.7.0-2~deb9u1
1:91.7.0-2~deb10u1
1:91.7.0-2~deb11u1
1:91.7.0-2
1:91.8.0-1~deb9u1
1:91.8.0-1~deb10u1
1:91.8.0-1~deb11u1
1:91.8.0-1
1:91.8.1-1
1:91.9.0-1~deb9u1
1:91.9.0-1~deb10u1
1:91.9.0-1~deb11u1
1:91.9.0-1
1:91.10.0-1~deb9u1
1:91.10.0-1~deb10u1
1:91.10.0-1~deb11u1
1:91.10.0-1
1:91.11.0-1~deb10u1
1:91.11.0-1~deb11u1
1:91.11.0-1
1:91.12.0-1~deb10u1
1:91.12.0-1~deb11u1
1:91.13.0-1~deb10u1
1:91.13.0-1~deb11u1

1:102.*

1:102.0~b4-1
1:102.0~b7-1
1:102.0.1-1
1:102.0.2-1
1:102.1.0-1
1:102.1.1-1
1:102.1.2-1
1:102.2.0-1
1:102.2.1-1
1:102.2.2-1
1:102.3.0-1~deb10u1
1:102.3.0-1~deb11u1
1:102.3.0-1
1:102.3.1-1
1:102.3.2-1
1:102.3.3-1
1:102.4.0-1~deb10u1
1:102.4.0-1~deb11u1
1:102.4.0-1
1:102.4.1-1
1:102.5.0-1~deb10u1
1:102.5.0-1~deb11u1
1:102.5.0-1
1:102.5.1-1
1:102.6.0-1~deb10u1
1:102.6.0-1~deb11u1
1:102.6.0-1
1:102.7.1-1
1:102.7.1+1-1
1:102.7.2-1
1:102.8.0-1~deb10u1
1:102.8.0-1~deb11u1
1:102.8.0-1
1:102.9.0-1~deb10u1
1:102.9.0-1~deb11u1
1:102.9.0-1
1:102.9.1-1
1:102.10.0-1~deb10u1
1:102.10.0-1~deb11u1
1:102.10.0-1
1:102.11.0-1~deb10u1
1:102.11.0-1~deb11u1
1:102.11.0-1
1:102.12.0-1~deb10u1
1:102.12.0-1~deb11u1
1:102.12.0-1~deb12u1
1:102.12.0-1
1:102.13.0-1~deb10u1
1:102.13.0-1~deb11u1
1:102.13.0-1~deb12u1
1:102.13.0-1
1:102.13.1-1~deb10u1
1:102.13.1-1~deb11u1
1:102.13.1-1~deb12u1
1:102.13.1-1
1:102.14.0-1~deb10u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / thunderbird

Package

Name
thunderbird
Purl
pkg:deb/debian/thunderbird?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:102.14.0-1~deb12u1

Affected versions

1:102.*

1:102.11.0-1
1:102.12.0-1~deb10u1
1:102.12.0-1~deb11u1
1:102.12.0-1~deb12u1
1:102.12.0-1
1:102.13.0-1~deb10u1
1:102.13.0-1~deb11u1
1:102.13.0-1~deb12u1
1:102.13.0-1
1:102.13.1-1~deb10u1
1:102.13.1-1~deb11u1
1:102.13.1-1~deb12u1
1:102.13.1-1
1:102.14.0-1~deb10u1
1:102.14.0-1~deb11u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / thunderbird

Package

Name
thunderbird
Purl
pkg:deb/debian/thunderbird?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:115.1.0-1

Affected versions

1:102.*

1:102.11.0-1
1:102.12.0-1~deb10u1
1:102.12.0-1~deb11u1
1:102.12.0-1~deb12u1
1:102.12.0-1
1:102.13.0-1~deb10u1
1:102.13.0-1~deb11u1
1:102.13.0-1~deb12u1
1:102.13.0-1
1:102.13.1-1~deb10u1
1:102.13.1-1~deb11u1
1:102.13.1-1~deb12u1
1:102.13.1-1
1:102.14.0-1~deb10u1
1:102.14.0-1~deb11u1
1:102.14.0-1~deb12u1
1:102.15.0-1~deb10u1
1:102.15.0-1~deb11u1
1:102.15.0-1~deb12u1
1:102.15.1-1~deb10u1
1:102.15.1-1~deb11u1
1:102.15.1-1~deb12u1

1:103.*

1:103.0~b5-1

1:104.*

1:104.0~b2-1

1:110.*

1:110.0~b4-1

1:112.*

1:112.0~b1-1

1:113.*

1:113.0~b3-1

1:114.*

1:114.0~b2-1

1:115.*

1:115.0~b4-1
1:115.0~b6-1
1:115.0-1
1:115.0.1-1
1:115.0.1-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}