CVE-2024-11703
published 2024-11-26CVE-2024-11703: On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects Firefox <…
medium5.7CVSS 3.1
AVPACLPRLUIRSUCHIHAN
On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects Firefox < 133.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 134.0-1 (sid) | firefox 134.0-1 (sid) |
| mozilla | firefox | < 133.0 | 133.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 133 | 133 |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
osv5.7MEDIUM
GHSA
GHSA-wjq6-6xvc-xr82: On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication
ghsa_unreviewed·2024-11-26
CVE-2024-11703 [CRITICAL] CWE-276 GHSA-wjq6-6xvc-xr82: On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication
On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects Firefox < 133.
OSV
CVE-2024-11703: On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication
osv·2024-11-26·CVSS 5.7
CVE-2024-11703 [MEDIUM] CVE-2024-11703: On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication
On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects Firefox < 133.
Red Hat
firefox: thunderbird: Password access without authentication via PIN bypass on Android
vendor_redhat·2024-11-26·CVSS 5.7
CVE-2024-11703 [MEDIUM] CWE-288 firefox: thunderbird: Password access without authentication via PIN bypass on Android
firefox: thunderbird: Password access without authentication via PIN bypass on Android
On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects Firefox < 133.
A flaw was found in Mozilla. The Mozilla Foundation's Security Advisory describes the following issue: On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 10) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Pack
Debian
CVE-2024-11703: firefox - On Android, Firefox may have inadvertently allowed viewing saved passwords witho...
vendor_debian·2024·CVSS 5.7
CVE-2024-11703 [MEDIUM] CVE-2024-11703: firefox - On Android, Firefox may have inadvertently allowed viewing saved passwords witho...
On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects Firefox < 133.
Scope: local
sid: resolved (fixed in 134.0-1)
Mozilla
Mozilla Foundation Security Advisory 2024-63: CVE-2024-11703
vendor_mozilla·CVSS 5.7
CVE-2024-11703 [MEDIUM] Mozilla Foundation Security Advisory 2024-63: CVE-2024-11703
Mozilla Foundation Security Advisory 2024-63
CVE: CVE-2024-11703
Product: Firefox
Impact: high
Fixed in: Firefox 133
No detection rules found.
No public exploits indexed.
2024-11-26
Published