CVE-2024-31392Mozilla Firefox FOR IOS vulnerability

5 documents5 sources
Severity
7.5HIGHNVD
EPSS
0.5%
top 35.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 3

Description

If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnerability affects Firefox for iOS < 124.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDmozilla/firefox< 124.0
CVEListV5mozilla/firefox_for_iosunspecified124

🔴Vulnerability Details

2
CVEList
CVE-2024-31392: If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnerab2024-04-03
GHSA
GHSA-w584-w92p-hx8h: If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnerab2024-04-03

📋Vendor Advisories

2
Debian
CVE-2024-31392: firefox - If an insecure element was added to a page after a delay, Firefox would not repl...2024
Mozilla
Mozilla Foundation Security Advisory 2024-17: CVE-2024-31392
CVE-2024-31392 — Mozilla Firefox FOR IOS vulnerability | cvebase