8.8 CVE-2024-8382

 

Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces would not be able to use them with elevated privileges, but their presence would indicate certain browser features had been used, such as when a user opened the Dev Tools console. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.
https://nvd.nist.gov/vuln/detail/CVE-2024-8382

Categories

CWE-NVD-noinfo

CWE-273 : Improper Check for Dropped Privileges
If the drop fails, the product will continue to run with the raised privileges, which might provide additional access to unprivileged users.

References


 

CPE

cpe start end
Configuration 1
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* < 130.0
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* < 115.15
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* >= 128.0 < 128.2


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry