CVE-2023-25741
Description
The Mozilla Foundation Security Advisory: When dragging and dropping an image cross-origin, the image size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until further review.
Statement
Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Acknowledgements
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Dohyun Lee (@l33d0hyun) of SSD Labs as the original reporter.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.