An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade firefox-x11Upgrade thunderbirdUpgrade firefox | Oct 7, 2024 | Oct 1, 2024 |
| Amazon Linux Ami 2 | — | Upgrade thunderbirdUpgrade thunderbird-debuginfoUpgrade firefoxUpgrade firefox-debuginfo | Nov 4, 2024 | Oct 1, 2024 |
| Debian | — | Upgrade firefox-esrUpgrade thunderbird | Oct 7, 2024 | Oct 1, 2024 |
| Oracle_linux | — | Upgrade thunderbirdUpgrade firefox-x11Upgrade firefox | Oct 16, 2024 | Oct 1, 2024 |
| Redhat_linux | — | Upgrade thunderbirdUpgrade firefox-debugsourceNo solution existsUpgrade firefox-debuginfoUpgrade firefoxUpgrade firefox-x11Upgrade thunderbird-debuginfoUpgrade thunderbird-debugsource | Oct 7, 2024 | Oct 1, 2024 |
| Rocky_linux | — | Upgrade firefox-debuginfoUpgrade firefoxUpgrade thunderbirdUpgrade thunderbird-debuginfoUpgrade firefox-debugsourceUpgrade thunderbird-debugsource | Nov 4, 2024 | Oct 1, 2024 |
| Suse | — | Upgrade mozillafirefox-translations-otherUpgrade mozillafirefox-translations-commonUpgrade mozjs128Upgrade mozillathunderbird-translations-otherUpgrade mozillafirefox-develUpgrade mozillathunderbird-translations-commonUpgrade mozillathunderbirdUpgrade mozillafirefoxUpgrade mozillafirefox-branding-upstreamUpgrade libmozjs-128-0Upgrade mozjs128-devel | Dec 31, 2024 | Oct 1, 2024 |
| Ubuntu | — | Upgrade firefox | Oct 8, 2024 | Oct 1, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub