CVE-2024-0749 — Origin Validation Error in Mozilla Firefox
CWE-346 — Origin Validation ErrorCWE-1021 — UI Misrepresentation / Clickjacking14 documents8 sources
Severity
4.3MEDIUMNVD
OSV6.5
EPSS
0.3%
top 44.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 23
Latest updateMar 4
Description
A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122 and Thunderbird < 115.7.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4
Affected Packages8 packages
Also affects: Debian Linux 10.0
🔴Vulnerability Details
6OSV▶
CVE-2024-0749: A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar↗2024-01-23
CVEList▶
CVE-2024-0749: A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar↗2024-01-23
📋Vendor Advisories
7Debian▶
CVE-2024-0749: firefox - A phishing site could have repurposed an `about:` dialog to show phishing conten...↗2024