PT-2024-8799 · Mozilla+10 · Firefox+11

Masato Kinugawa

·

Published

2024-11-25

·

Updated

2026-05-19

·

CVE-2024-11694

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Firefox versions prior to 133 Firefox ESR versions prior to 128.5 Firefox ESR versions prior to 115.18 Thunderbird versions prior to 133 Thunderbird versions prior to 128.5 Thunderbird versions prior to 115.18
Description: The issue is related to Enhanced Tracking Protection's Strict mode, which may have allowed a Content Security Policy (CSP) frame-src bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This could have exposed users to malicious frames masquerading as legitimate content, potentially allowing an attacker to perform a DOM-based XSS attack by exploiting the lack of protection for the web page structure.
Recommendations: For Firefox versions prior to 133, update to version 133 or later. For Firefox ESR versions prior to 128.5, update to version 128.5 or later. For Firefox ESR versions prior to 115.18, update to version 115.18 or later. For Thunderbird versions prior to 133, update to version 133 or later. For Thunderbird versions prior to 128.5, update to version 128.5 or later. For Thunderbird versions prior to 115.18, update to version 115.18 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:10591
ALSA-2024:10592
ALSA-2024:10702
ALSA-2024:10752
ALSA-2026:18479
ALT-PU-2024-16375
ALT-PU-2024-16377
ALT-PU-2024-16378
ALT-PU-2025-1049
ALT-PU-2025-2027
ALT-PU-2025-2230
BDU:2024-10431
CESA-2024_10591
CESA-2024_10752
CVE-2024-11694
DLA-3969-1
DLA-3971-1
DSA-5820-1
DSA-5821-1
INFSA-2024_10591
INFSA-2024_10592
INFSA-2024_10702
INFSA-2024_10752
MGASA-2024-0383
MGASA-2024-0384
OESA-2024-2523
OESA-2025-1835
OPENSUSE-SU-2024:14533-1
OPENSUSE-SU-2024:14542-1
OPENSUSE-SU-2024:14572-1
OPENSUSE-SU-2024:14583-1
OPENSUSE-SU-2024_4086-1
OPENSUSE-SU-2024_4148-1
RHSA-2024:10591
RHSA-2024:10592
RHSA-2024:10667
RHSA-2024:10702
RHSA-2024:10703
RHSA-2024:10704
RHSA-2024:10710
RHSA-2024:10733
RHSA-2024:10734
RHSA-2024:10742
RHSA-2024:10743
RHSA-2024:10745
RHSA-2024:10748
RHSA-2024:10752
RHSA-2024:10844
RHSA-2024:10848
RHSA-2024:10849
RHSA-2024:10880
RHSA-2024:10881
RHSA-2024_10591
RHSA-2024_10592
RHSA-2024_10702
RHSA-2024_10752
RLSA-2024:10591
RLSA-2024:10752
SUSE-SU-2024:4074-1
SUSE-SU-2024:4086-1
SUSE-SU-2024:4148-1
USN-7134-1
USN-7193-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Thunderbird
Ubuntu