CVE-2024-5687
published 2024-06-11CVE-2024-5687: If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The…
medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The triggering principal is used to calculate many values, including the `Referer` and `Sec-*` headers, meaning there is the potential for incorrect security checks within the browser in addition to incorrect or misleading information sent to remote websites.
*This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 127.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | < 127.0 | 127.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 127 | 127 |
GHSA
GHSA-4c8g-9w4h-h6xm: If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect
ghsa_unreviewed·2024-06-11
CVE-2024-5687 [MEDIUM] CWE-284 GHSA-4c8g-9w4h-h6xm: If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect
If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The triggering principal is used to calculate many values, including the `Referer` and `Sec-*` headers, meaning there is the potential for incorrect security checks within the browser in addition to incorrect or misleading information sent to remote websites.
*This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 127.
Debian
CVE-2024-5687: firefox - If a specific sequence of actions is performed when opening a new tab, the trigg...
vendor_debian·2024·CVSS 5.3
CVE-2024-5687 [MEDIUM] CVE-2024-5687: firefox - If a specific sequence of actions is performed when opening a new tab, the trigg...
If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The triggering principal is used to calculate many values, including the `Referer` and `Sec-*` headers, meaning there is the potential for incorrect security checks within the browser in addition to incorrect or misleading information sent to remote websites. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 127.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2024-25: CVE-2024-5687
vendor_mozilla·CVSS 5.3
CVE-2024-5687 [MEDIUM] Mozilla Foundation Security Advisory 2024-25: CVE-2024-5687
Mozilla Foundation Security Advisory 2024-25
CVE: CVE-2024-5687
Product: Firefox
Impact: high
Fixed in: Firefox 127
No detection rules found.
No public exploits indexed.
2024-06-11
Published