PT-2024-10437 · Mozilla+9 · Thunderbird+11

Hafiizh

·

Published

2024-10-29

·

Updated

2026-02-02

·

CVE-2024-10462

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 132 Firefox ESR versions prior to 128.4 Thunderbird versions prior to 128.4 Thunderbird versions prior to 132
Description The issue is related to the truncation of long URLs, which could allow origin spoofing in permission prompts. This may enable a remote attacker to impact data integrity through authentication bypass via spoofing.
Recommendations For Firefox versions prior to 132, update to version 132 or later. For Firefox ESR versions prior to 128.4, update to version 128.4 or later. For Thunderbird versions prior to 128.4, update to version 128.4 or later. For Thunderbird versions prior to 132, update to version 132 or later.

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:8726
ALSA-2024:8729
ALSA-2024:8790
ALSA-2024:8793
ALSA-2024:9552
ALSA-2024:9554
ALT-PU-2024-15089
ALT-PU-2024-15091
ALT-PU-2024-15092
ALT-PU-2024-15839
ALT-PU-2024-15840
ALT-PU-2024-15841
BDU:2025-00973
CESA-2024_8729
CESA-2024_8790
CVE-2024-10462
DLA-3943-1
DLA-3944-1
DSA-5801-1
DSA-5803-1
INFSA-2024_8726
INFSA-2024_8729
INFSA-2024_8790
INFSA-2024_8793
INFSA-2024_9552
INFSA-2024_9554
MGASA-2024-0349
MGASA-2024-0350
OESA-2024-2342
OESA-2025-1265
OESA-2025-1268
OESA-2025-1835
OPENSUSE-SU-2024:14438-1
OPENSUSE-SU-2024:14461-1
OPENSUSE-SU-2024:14483-1
OPENSUSE-SU-2024:14572-1
OPENSUSE-SU-2024_3898-1
OPENSUSE-SU-2024_4050-1
RHSA-2024:8720
RHSA-2024:8721
RHSA-2024:8722
RHSA-2024:8723
RHSA-2024:8724
RHSA-2024:8725
RHSA-2024:8726
RHSA-2024:8727
RHSA-2024:8728
RHSA-2024:8729
RHSA-2024:8790
RHSA-2024:8793
RHSA-2024:9015
RHSA-2024:9016
RHSA-2024:9017
RHSA-2024:9018
RHSA-2024:9019
RHSA-2024:9552
RHSA-2024:9554
RHSA-2024_8726
RHSA-2024_8729
RHSA-2024_8790
RHSA-2024_8793
RHSA-2024_9552
RHSA-2024_9554
RLSA-2024:8726
RLSA-2024:8729
RLSA-2024:8790
RLSA-2024:8793
ROSA-SA-2025-2563
SUSE-SU-2024:3898-1
SUSE-SU-2024:3899-1
SUSE-SU-2024:4050-1
USN-7086-1
USN-7991-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Firefox Esr
Linuxmint
Red Hat
Rocky Linux
Suse
Thunderbird
Ubuntu