CVE-2024-0749Origin Validation Error in Mozilla Firefox

Severity
4.3MEDIUMNVD
OSV6.5
EPSS
0.3%
top 44.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 23
Latest updateMar 4

Description

A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122 and Thunderbird < 115.7.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages8 packages

CVEListV5mozilla/firefoxunspecified122
NVDmozilla/firefox< 122.0
CVEListV5mozilla/thunderbirdunspecified115.7
NVDmozilla/firefox_esr< 115.7
NVDmozilla/thunderbird< 115.7

Also affects: Debian Linux 10.0

🔴Vulnerability Details

6
OSV
thunderbird vulnerabilities2024-03-04
OSV
firefox regressions2024-02-07
OSV
firefox vulnerabilities2024-01-29
OSV
CVE-2024-0749: A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar2024-01-23
CVEList
CVE-2024-0749: A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar2024-01-23

📋Vendor Advisories

7
Ubuntu
Thunderbird vulnerabilities2024-03-04
Ubuntu
Firefox vulnerabilities2024-01-29
Red Hat
Mozilla: Phishing site popup could show local origin in address bar2024-01-23
Debian
CVE-2024-0749: firefox - A phishing site could have repurposed an `about:` dialog to show phishing conten...2024
Mozilla
Mozilla Foundation Security Advisory 2024-04: CVE-2024-0749
CVE-2024-0749 — Origin Validation Error in Mozilla | cvebase