CVE-2024-11702Inappropriate Encoding for Output Context in Mozilla Firefox

Severity
7.5HIGHNVD
EPSS
0.3%
top 51.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 26

Description

Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboard history if enabled. This vulnerability affects Firefox < 133 and Thunderbird < 133.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

CVEListV5mozilla/firefoxunspecified133
NVDmozilla/firefox< 133.0
CVEListV5mozilla/thunderbirdunspecified133
NVDmozilla/thunderbird< 133.0

🔴Vulnerability Details

3
GHSA
GHSA-7r4q-q89f-2mcg: Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboar2024-11-26
OSV
CVE-2024-11702: Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboar2024-11-26
CVEList
CVE-2024-11702: Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboar2024-11-26

📋Vendor Advisories

4
Red Hat
firefox: thunderbird: Inadequate Clipboard Protection in Private Browsing Mode on Android2024-11-26
Debian
CVE-2024-11702: firefox - Copying sensitive information from Private Browsing tabs on Android, such as pas...2024
Mozilla
Mozilla Foundation Security Advisory 2024-67: CVE-2024-11702
Mozilla
Mozilla Foundation Security Advisory 2024-63: CVE-2024-11702
CVE-2024-11702 — Mozilla Firefox vulnerability | cvebase