216.73.217.22

CVE-2024-8382

· Published 03/09/2024 13:15 · Modified 06/09/2024 17:15

Labels: CVE-2024-8382 2024-09-03CVE-2024-8382NVD-CWE-noinfo[email protected]

Essential information

Published
03/09/2024 13:15
Modified
06/09/2024 17:15
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces would not be able to use them with elevated privileges, but their presence would indicate certain browser features had been used, such as when a user opened the Dev Tools console. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.

NVD status

Status
Modified — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mozilla / firefox cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozilla / firefox esr cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
mozilla / firefox esr cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*

References