Severity
6.1MEDIUMNVD
OSV9.8
EPSS
0.3%
top 49.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 3
Latest updateSep 23

Description

If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages7 packages

CVEListV5mozilla/firefoxunspecified130
NVDmozilla/firefox< 130.0
CVEListV5mozilla/firefox_esrunspecified128.2
NVDmozilla/firefox_esr< 128.2
Ubuntumozilla/firefox< 130.0+build2-0ubuntu0.20.04.1

🔴Vulnerability Details

5
OSV
firefox regressions2024-09-23
OSV
firefox vulnerabilities2024-09-05
CVEList
CVE-2024-8386: If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing2024-09-03
GHSA
GHSA-p34f-6xg6-mcrp: If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing2024-09-03
OSV
CVE-2024-8386: If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing2024-09-03

📋Vendor Advisories

6
Ubuntu
Firefox vulnerabilities2024-09-05
Red Hat
mozilla: SelectElements could be shown over another site if popups are allowed2024-09-03
Debian
CVE-2024-8386: firefox - If a site had been granted the permission to open popup windows, it could cause ...2024
Mozilla
Mozilla Foundation Security Advisory 2024-43: CVE-2024-8386
Mozilla
Mozilla Foundation Security Advisory 2024-40: CVE-2024-8386
CVE-2024-8386 — Open Redirect in Mozilla Firefox | cvebase