CVE-2024-8382Improper Check for Dropped Privileges in Mozilla Firefox

Severity
8.8HIGHNVD
OSV9.8OSV9.6
EPSS
0.2%
top 52.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 3
Latest updateSep 23

Description

Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces would not be able to use them with elevated privileges, but their presence would indicate certain browser features had been used, such as when a user opened the Dev Tools console. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages8 packages

CVEListV5mozilla/firefoxunspecified130
NVDmozilla/firefox< 130.0
CVEListV5mozilla/firefox_esrunspecified128.2+1
NVDmozilla/firefox_esr128.0128.2+1
Ubuntumozilla/firefox< 130.0+build2-0ubuntu0.20.04.1+1

🔴Vulnerability Details

6
OSV
firefox regressions2024-09-23
OSV
thunderbird vulnerabilities2024-09-09
OSV
firefox vulnerabilities2024-09-05
OSV
CVE-2024-8382: Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events2024-09-03
GHSA
GHSA-ph32-hgpc-r5j4: Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events2024-09-03

📋Vendor Advisories

9
Ubuntu
Thunderbird vulnerabilities2024-09-09
Ubuntu
Firefox vulnerabilities2024-09-05
Red Hat
mozilla: Internal event interfaces were exposed to web content when browser EventHandler listener callbacks ran2024-09-03
Debian
CVE-2024-8382: firefox - Internal browser event interfaces were exposed to web content when privileged Ev...2024
Mozilla
Mozilla Foundation Security Advisory 2024-43: CVE-2024-8382
CVE-2024-8382 — Improper Check for Dropped Privileges | cvebase