An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbirdUpgrade firefoxUpgrade firefox-x11 | Oct 7, 2024 | Oct 1, 2024 |
| Amazon Linux Ami 2 | — | Upgrade firefox-debuginfoUpgrade firefoxUpgrade thunderbird-debuginfoUpgrade thunderbird | Nov 4, 2024 | Oct 1, 2024 |
| Debian | — | Upgrade thunderbirdUpgrade firefox-esr | Oct 7, 2024 | Oct 1, 2024 |
| Oracle_linux | — | Upgrade thunderbirdUpgrade firefox-x11Upgrade firefox | Oct 16, 2024 | Oct 1, 2024 |
| Redhat_linux | — | Upgrade firefox-debugsourceUpgrade thunderbird-debuginfoUpgrade thunderbirdUpgrade firefox-x11Upgrade firefox-debuginfoUpgrade thunderbird-debugsourceUpgrade firefoxNo solution exists | Oct 7, 2024 | Oct 1, 2024 |
| Rocky_linux | — | Upgrade firefox-debuginfoUpgrade thunderbirdUpgrade firefoxUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoUpgrade firefox-debugsource | Nov 4, 2024 | Oct 1, 2024 |
| Suse | — | Upgrade MozillaThunderbird-translations-commonUpgrade libmozjs-128-0Upgrade mozillafirefox-branding-upstreamUpgrade MozillaFirefox-develUpgrade MozillaThunderbird-translations-otherUpgrade MozillaFirefox-translations-commonUpgrade MozillaThunderbirdUpgrade mozjs128-develUpgrade mozjs128Upgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox | Dec 31, 2024 | Oct 1, 2024 |
| Ubuntu | — | Upgrade firefox | Oct 8, 2024 | Oct 1, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub