PT-2024-7811 · Mozilla+9 · Thunderbird+11
Satoki Tsuji
·
Published
2024-10-01
·
Updated
2026-02-02
·
CVE-2024-9398
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 131
Firefox ESR versions prior to 128.3
Thunderbird versions prior to 128.3
Thunderbird versions prior to 131
Description
This issue is related to the
window.open function in Mozilla browsers, which can lead to information disclosure through inconsistency. An attacker could determine if an application that implements a specific protocol handler is installed by checking the result of calls to window.open with specifically set protocol handlers. This could allow a remote attacker to gain unauthorized access to protected information.Recommendations
For Firefox versions prior to 131, update to version 131 or later to resolve the issue.
For Firefox ESR versions prior to 128.3, update to version 128.3 or later to resolve the issue.
For Thunderbird versions prior to 128.3, update to version 128.3 or later to resolve the issue.
For Thunderbird versions prior to 131, update to version 131 or later to resolve the issue.
As a temporary workaround, consider restricting the use of the
window.open function with specifically set protocol handlers until a patch is available.Fix
Information Disclosure
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Firefox Esr
Linuxmint
Red Hat
Rocky Linux
Suse
Thunderbird
Ubuntu