CVE-2024-5687Improper Access Control in Mozilla Firefox

Severity
5.3MEDIUMNVD
EPSS
0.6%
top 30.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11
Latest updateJul 31

Description

If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The triggering principal is used to calculate many values, including the `Referer` and `Sec-*` headers, meaning there is the potential for incorrect security checks within the browser in addition to incorrect or misleading information sent to remote websites. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5mozilla/firefoxunspecified127
NVDmozilla/firefox< 127.0

🔴Vulnerability Details

2
CVEList
CVE-2024-5687: If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect2024-06-11
GHSA
GHSA-4c8g-9w4h-h6xm: If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect2024-06-11

📋Vendor Advisories

2
Debian
CVE-2024-5687: firefox - If a specific sequence of actions is performed when opening a new tab, the trigg...2024
Mozilla
Mozilla Foundation Security Advisory 2024-25: CVE-2024-5687

📄Research Papers

1
arXiv
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights2024-07-31
CVE-2024-5687 — Improper Access Control in Mozilla | cvebase