When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until further review. This vulnerability affects Firefox < 110.
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Link | Tags |
---|---|
https://www.mozilla.org/security/advisories/mfsa2023-05/ | vendor advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=1813376 | issue tracking permissions required |
https://bugzilla.mozilla.org/show_bug.cgi?id=1437126 | vendor advisory issue tracking |
https://bugzilla.mozilla.org/show_bug.cgi?id=1812611 | vendor advisory issue tracking exploit |