Mozilla Firefox Vulnerability: Error Messages Could Reveal Cross-Origin Information

CVE-2024-4769
Currently unrated 🤨

Key Information

Vendor
Mozilla
Status
Firefox
Firefox Esr
Thunderbird
Vendor
CVE Published:
14 May 2024

Summary

When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

Affected Version(s)

Firefox < 126

Firefox ESR < 115.11

Thunderbird < 115.11

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Shaheen Fazim
.