CVE-2024-11694

Name
CVE-2024-11694
Description
Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading as legitimate content. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, Thunderbird < 128.5, and Thunderbird < 115.18.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
https://bugzilla.mozilla.org/show_bug.cgi?id=1924167
https://www.mozilla.org/security/advisories/mfsa2024-63/
https://www.mozilla.org/security/advisories/mfsa2024-64/
https://www.mozilla.org/security/advisories/mfsa2024-65/
https://www.mozilla.org/security/advisories/mfsa2024-67/
https://www.mozilla.org/security/advisories/mfsa2024-68/
security@mozilla.org https://www.mozilla.org/security/advisories/mfsa2024-70/

Match rules

CPE URI Source package Min version Max version
firefox >= unspecified < 133
firefox-esr >= unspecified < 128.5
firefox-esr >= unspecified < 115.18
thunderbird >= unspecified < 133
thunderbird >= unspecified < 128.5

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
thunderbird 3.20-community 128.5.0-r0 Patrycja Rosa <alpine@ptrcnull.me> fixed
firefox 3.20-community 132.0.2-r0 Patrycja Rosa <alpine@ptrcnull.me> fixed
firefox-esr 3.20-community 115.18.0-r0 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable
thunderbird edge-community 128.5.1-r0 Patrycja Rosa <alpine@ptrcnull.me> fixed