PT-2024-39306 · Mozilla+1 · Firefox For Android+1
Thomas Orlita
·
Published
2024-09-17
·
Updated
2025-11-19
·
CVE-2024-8897
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Firefox for Android versions prior to 130.0.1
Description:
Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to spoof the address bar contents. This can lead to a malicious site appearing to have the same URL as the trusted site.
Recommendations:
For Firefox for Android versions prior to 130.0.1, update to version 130.0.1 or later to resolve the issue. As a temporary workaround, consider avoiding the use of open redirects on trusted sites to minimize the risk of exploitation.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Firefox For Android