CVE-2024-11694Cross-site Scripting in Mozilla Firefox

CWE-79Cross-site Scripting15 documents8 sources
Severity
6.1MEDIUMNVD
OSV4.3
EPSS
0.1%
top 67.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 26
Latest updateJan 9

Description

Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading as legitimate content. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, Thunderbird < 128.5, and Thunderbird < 115.18.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages7 packages

CVEListV5mozilla/firefoxunspecified133
NVDmozilla/firefox116.0128.5.0+2
CVEListV5mozilla/firefox_esrunspecified128.5+1
CVEListV5mozilla/thunderbirdunspecified133+2
NVDmozilla/thunderbird116.0128.5.0+2

🔴Vulnerability Details

4
OSV
firefox vulnerabilities2024-12-03
OSV
CVE-2024-11694: Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim2024-11-26
CVEList
CVE-2024-11694: Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim2024-11-26
GHSA
GHSA-mjcw-r3mg-3848: Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim2024-11-26

📋Vendor Advisories

10
Ubuntu
Thunderbird vulnerability2025-01-09
Ubuntu
Firefox vulnerabilities2024-12-03
Red Hat
firefox: thunderbird: CSP Bypass and XSS Exposure via Web Compatibility Shims2024-11-26
Debian
CVE-2024-11694: firefox - Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP ...2024
Mozilla
Mozilla Foundation Security Advisory 2024-63: CVE-2024-11694
CVE-2024-11694 — Cross-site Scripting in Mozilla | cvebase