When checking if the Browsing Context had been discarded...
High severity
Unreviewed
Published
Sep 11, 2023
to the GitHub Advisory Database
•
Updated Sep 19, 2024
Description
Published by the National Vulnerability Database
Sep 11, 2023
Published to the GitHub Advisory Database
Sep 11, 2023
Last updated
Sep 19, 2024
When checking if the Browsing Context had been discarded in
HttpBaseChannel
, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private session had ended. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.References