Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-Cookie response headers that would have been honored by the browser. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbirdUpgrade firefoxUpgrade firefox-x11 | Feb 29, 2024 | Feb 20, 2024 |
| Alpine Linux | — | Upgrade thunderbirdUpgrade firefoxUpgrade firefox-esr | Aug 22, 2024 | Feb 20, 2024 |
| Amazon Linux Ami 2 | — | Upgrade thunderbirdUpgrade thunderbird-debuginfoUpgrade firefoxUpgrade firefox-debuginfo | Mar 5, 2024 | Feb 20, 2024 |
| Centos_linux | — | Upgrade thunderbirdUpgrade firefoxUpgrade firefox-debuginfoUpgrade thunderbird-debuginfo | Mar 7, 2024 | Feb 20, 2024 |
| Debian | — | Upgrade thunderbirdUpgrade firefox-esr | Feb 23, 2024 | Feb 20, 2024 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird-bin.Upgrade mail-client/thunderbird.Upgrade www-client/firefox.Upgrade www-client/firefox-bin. | May 6, 2024 | Feb 20, 2024 |
| Mfsa2024 05 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 123.0 | Feb 21, 2024 | Feb 20, 2024 |
| Mfsa2024 06 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 115.8 | Feb 21, 2024 | Feb 20, 2024 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 115.8 | Feb 21, 2024 | Feb 20, 2024 |
| Oracle_linux | — | Upgrade firefox-x11Upgrade firefoxUpgrade thunderbird | Feb 24, 2024 | Feb 20, 2024 |
| Redhat_linux | — | Upgrade firefox-x11Upgrade firefox-debugsourceUpgrade firefox-debuginfoUpgrade thunderbird-debuginfoNo solution existsUpgrade thunderbirdUpgrade thunderbird-debugsourceUpgrade firefox | Feb 23, 2024 | Feb 20, 2024 |
| Rocky_linux | — | Upgrade firefox-debugsourceUpgrade firefoxUpgrade firefox-debuginfo | Mar 13, 2024 | Feb 20, 2024 |
| Suse | — | Upgrade MozillaFirefoxUpgrade MozillaFirefox-translations-otherUpgrade mozillafirefox-branding-upstreamUpgrade MozillaThunderbirdUpgrade MozillaThunderbird-translations-commonUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-commonUpgrade MozillaThunderbird-translations-other | Feb 22, 2024 | Feb 20, 2024 |
| Ubuntu | — | Upgrade firefoxUpgrade thunderbird | Feb 23, 2024 | Feb 20, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub