CVE-2024-7524
06.08.2024, 13:15
Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic" mode, an attacker able to inject an HTML element could have used a DOM Clobbering attack on some of the shims and achieved XSS, bypassing the CSP strict-dynamic protection. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 < 129.0 |
mozilla | firefox_esr | 𝑥 < 115.14 |
mozilla | firefox_esr | 116.0 ≤ 𝑥 < 128.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||
mozjs102 |
| ||||||||||||
mozjs115 |
| ||||||||||||
mozjs38 |
| ||||||||||||
mozjs52 |
| ||||||||||||
mozjs68 |
| ||||||||||||
mozjs78 |
| ||||||||||||
mozjs91 |
| ||||||||||||
thunderbird |
|