Firefox Vulnerability: Permission Leak Due to Embed or Object Elements
CVE-2024-10458
7.5HIGH
Summary
A permission leak could have occurred from a trusted site to an untrusted site via embed
or object
elements. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
Affected Version(s)
Firefox < 132
Firefox ESR < 128.4
Firefox ESR < 115.17
Refferences
https://bugzilla.mozilla.org/show_bug.cgi?id=1921733
https://www.mozilla.org/security/advisories/mfsa2024-55/
https://www.mozilla.org/security/advisories/mfsa2024-56/
https://www.mozilla.org/security/advisories/mfsa2024-57/
https://www.mozilla.org/security/advisories/mfsa2024-58/
https://www.mozilla.org/security/advisories/mfsa2024-59/
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
James Lee