CVE-2023-6868

Source
https://cve.org/CVERecord?id=CVE-2023-6868
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-6868.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-6868
Downstream
Related
Published
2023-12-19T14:15:07.983Z
Modified
2026-03-15T14:48:40.075393Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. This bug only affects Firefox on Android. This vulnerability affects Firefox < 121.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-6868.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "121.0"
            }
        ]
    }
]