An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade firefox-x11Upgrade firefoxUpgrade thunderbird | Oct 7, 2024 | Oct 1, 2024 |
| Amazon Linux Ami 2 | — | Upgrade firefoxUpgrade thunderbirdUpgrade firefox-debuginfoUpgrade thunderbird-debuginfo | Nov 4, 2024 | Oct 1, 2024 |
| Debian | — | Upgrade firefox-esrUpgrade thunderbird | Oct 7, 2024 | Oct 1, 2024 |
| Oracle_linux | — | Upgrade firefoxUpgrade firefox-x11Upgrade thunderbird | Oct 16, 2024 | Oct 1, 2024 |
| Redhat_linux | — | Upgrade firefox-x11Upgrade firefoxUpgrade thunderbird-debugsourceUpgrade thunderbirdUpgrade firefox-debugsourceNo solution existsUpgrade firefox-debuginfoUpgrade thunderbird-debuginfo | Oct 7, 2024 | Oct 1, 2024 |
| Rocky_linux | — | Upgrade thunderbird-debuginfoUpgrade firefox-debugsourceUpgrade thunderbird-debugsourceUpgrade firefox-debuginfoUpgrade thunderbirdUpgrade firefox | Nov 4, 2024 | Oct 1, 2024 |
| Suse | — | Upgrade MozillaFirefox-translations-otherUpgrade MozillaFirefoxUpgrade mozjs128Upgrade mozjs128-develUpgrade MozillaThunderbird-translations-otherUpgrade mozillafirefox-branding-upstreamUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-develUpgrade MozillaThunderbirdUpgrade libmozjs-128-0Upgrade MozillaThunderbird-translations-common | Dec 31, 2024 | Oct 1, 2024 |
| Ubuntu | — | Upgrade firefox | Oct 8, 2024 | Oct 1, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub