Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

John-Mark Gurney

#52013of 56,330
5Total CVSS
Vulnerabilities · 1
PT-2023-7881
5.0
2023-12-19
Mozilla · Firefox · CVE-2023-6868
**Name of the Vulnerable Software and Affected Versions** Firefox versions prior to 121 **Description** The user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. The issue is related to insufficient protection of service data and may allow a remote attacker to gain unauthorized access to limited functions. This bug only affects Firefox on Android. **Recommendations** For Firefox versions prior to 121, update to version 121 or later to resolve the issue. As a temporary workaround, consider restricting access to push requests until a patch is available. Avoid using the `VAPID` parameter in push requests until the issue is resolved.