PT-2024-5897 · Mozilla+10 · Firefox+10

D7

·

Published

2024-09-03

·

Updated

2025-07-10

·

CVE-2024-8383

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 130 Firefox ESR versions prior to 128.2 Firefox ESR versions prior to 115.15
Description The issue is related to the browser's handling of certain schemes, specifically the Usenet-related schemes "news:" and "snews:". Normally, Firefox asks for confirmation before opening these schemes, but in this case, it did not. This could allow an unscrupulous program to register itself as a handler and be launched by a website at will. The estimated number of potentially affected devices is not specified.
Recommendations For Firefox versions prior to 130, update to version 130 or later. For Firefox ESR versions prior to 128.2, update to version 128.2 or later. For Firefox ESR versions prior to 115.15, update to version 115.15 or later. As a temporary workaround, consider disabling the handling of "news:" and "snews:" schemes until a patch is available. Restrict access to custom URL scheme handlers to minimize the risk of exploitation. Avoid using untrusted newsreaders or applications that may register themselves as handlers for these schemes.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:6681
ALSA-2024:6682
ALT-PU-2024-13895
ALT-PU-2024-13898
ALT-PU-2024-15839
ALT-PU-2024-15840
ALT-PU-2025-2672
ALT-PU-2025-8904
BDU:2024-06700
CESA-2024_6682
CVE-2024-8383
DLA-3869-1
DLA-3882-1
DSA-5765-1
DSA-5767-1
INFSA-2024_6681
INFSA-2024_6682
MGASA-2024-0325
MGASA-2024-0332
MGASA-2024-0334
OESA-2024-2139
OESA-2025-1265
OESA-2025-1268
OPENSUSE-SU-2024:14358-1
OPENSUSE-SU-2024:14369-1
OPENSUSE-SU-2024:14572-1
OPENSUSE-SU-2024_3157-1
RHSA-2024:6681
RHSA-2024:6682
RHSA-2024:6838
RHSA-2024:6891
RHSA-2024:6892
RHSA-2024_6681
RHSA-2024_6682
RLSA-2024:6681
RLSA-2024:6682
ROSA-SA-2025-2640
SUSE-SU-2024:3152-1
SUSE-SU-2024:3157-1
USN-6992-1
USN-6992-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu