PT-2024-5898 · Mozilla+9 · Firefox+11

Hafiizh

+1

·

Published

2024-09-03

·

Updated

2025-03-21

·

CVE-2024-8386

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 130 Firefox ESR versions prior to 128.2 Thunderbird versions prior to 128.2
Description The issue is related to incorrect restriction of visualized user interface layers, which could allow a remote attacker to perform spoofing attacks. If a site has permission to open popup windows, it could cause Select elements to appear on top of another site.
Recommendations For Firefox versions prior to 130, update to version 130 or later to resolve the issue. For Firefox ESR versions prior to 128.2, update to version 128.2 or later to resolve the issue. For Thunderbird versions prior to 128.2, update to version 128.2 or later to resolve the issue.

Fix

Clickjacking

Open Redirect

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:6681
ALSA-2024:6682
ALSA-2024:6683
ALSA-2024:6684
ALT-PU-2024-13895
ALT-PU-2024-13897
ALT-PU-2024-13898
ALT-PU-2024-15839
ALT-PU-2024-15840
ALT-PU-2024-15841
BDU:2024-06701
CESA-2024_6682
CESA-2024_6684
CVE-2024-8386
INFSA-2024_6681
INFSA-2024_6682
INFSA-2024_6683
INFSA-2024_6684
MGASA-2024-0325
MGASA-2024-0332
MGASA-2024-0334
OESA-2024-2241
OESA-2025-1322
OESA-2025-1323
OPENSUSE-SU-2024:14358-1
OPENSUSE-SU-2024:14369-1
OPENSUSE-SU-2024:14572-1
OPENSUSE-SU-2024_3157-1
OPENSUSE-SU-2024_3507-1
RHSA-2024:6681
RHSA-2024:6682
RHSA-2024:6683
RHSA-2024:6684
RHSA-2024:6719
RHSA-2024:6720
RHSA-2024:6721
RHSA-2024:6722
RHSA-2024:6723
RHSA-2024:6816
RHSA-2024:6838
RHSA-2024:6891
RHSA-2024:6892
RHSA-2024_6681
RHSA-2024_6682
RHSA-2024_6683
RHSA-2024_6684
RLSA-2024:6681
RLSA-2024:6682
RLSA-2024:6683
RLSA-2024:6684
SUSE-SU-2024:3152-1
SUSE-SU-2024:3157-1
SUSE-SU-2024:3507-1
USN-6992-1
USN-6992-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Firefox Esr
Linuxmint
Red Hat
Rocky Linux
Suse
Thunderbird
Ubuntu