VDB

CISA-2024-7525

CISA-2024-7525 PUBLISHED CVSS 9.1 CRITICAL

Reported by mozilla · Published August 6, 2024

It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

Risk Scores

CVSS 3.1
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
MozillaFirefoxunspecified
MozillaFirefox ESRunspecified
MozillaFirefox ESRunspecified
MozillaThunderbirdunspecified
MozillaThunderbirdunspecified
MozillaFirefoxunspecified, *
MozillaThunderbirdunspecified, unspecified, unspecified
MozillaFirefox ESRunspecified, unspecified, unspecified
mozillafirefox0, 0
mozillafirefox_esr0, 0, 0

Timeline

  • Aug 6, 2024 CVE Published
  • Aug 6, 2024 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›