PT-2024-1352 · Mozilla+4 · Firefox+4

Young Min Kim

·

Published

2024-01-23

·

Updated

2025-03-14

·

CVE-2024-0748

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 122
Description The issue is related to insufficient access control in Mozilla Firefox, allowing a remote attacker to exploit it and set an arbitrary URI in the address bar or browser history. A compromised content process could update the document URI, enabling an attacker to perform such actions.
Recommendations For versions prior to 122, update to version 122 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive features until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-1368
ALT-PU-2024-13898
ALT-PU-2024-15839
ALT-PU-2024-15840
BDU:2024-00806
CVE-2024-0748
OESA-2025-1265
OESA-2025-1268
OPENSUSE-SU-2024:13626-1
OPENSUSE-SU-2024:14572-1
USN-6610-1
USN-6610-2

Affected Products

Alt Linux
Astra Linux
Linuxmint
Firefox
Ubuntu