CVE-2024-8900
published 2024-09-17CVE-2024-8900: An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects…
high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129, Firefox ESR < 128.3, and Thunderbird < 128.3.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 129.0-1 (sid) | firefox 129.0-1 (sid) |
| debian | thunderbird | < firefox 129.0-1 (sid) | firefox 129.0-1 (sid) |
| mozilla | firefox | < 129.0 | 129.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 129 | 129 |
| mozilla | firefox_esr | >= unspecified < 128.3 | 128.3 |
| mozilla | thunderbird | >= 0 < 1:128.3.0esr-1 | 1:128.3.0esr-1 |
| mozilla | thunderbird | >= 0 < 1:128.3.0esr-1 | 1:128.3.0esr-1 |
| mozilla | thunderbird | >= unspecified < 128.3 | 128.3 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH
OSV
CVE-2024-8900: An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events
osv·2024-09-17·CVSS 7.5
CVE-2024-8900 [HIGH] CVE-2024-8900: An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events
An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129, Firefox ESR < 128.3, and Thunderbird < 128.3.
GHSA
GHSA-97x9-7h6v-3jx9: An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events
ghsa_unreviewed·2024-09-17
CVE-2024-8900 [HIGH] CWE-732 GHSA-97x9-7h6v-3jx9: An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events
An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129.
Red Hat
firefox: Clipboard write permission bypass
vendor_redhat·2024-09-17·CVSS 7.5
CVE-2024-8900 [HIGH] firefox: Clipboard write permission bypass
firefox: Clipboard write permission bypass
An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129, Firefox ESR < 128.3, and Thunderbird < 128.3.
The Mozilla Foundation's Security Advisory: An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 10) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Out of support scope
Package: firefox (Red Hat Enterprise Linux 9) - Affected
Package: firefox-flatpak-container (Red H
Debian
CVE-2024-8900: firefox - An attacker could write data to the user's clipboard, bypassing the user prompt,...
vendor_debian·2024·CVSS 7.5
CVE-2024-8900 [HIGH] CVE-2024-8900: firefox - An attacker could write data to the user's clipboard, bypassing the user prompt,...
An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129, Firefox ESR < 128.3, and Thunderbird < 128.3.
Scope: local
sid: resolved (fixed in 129.0-1)
Mozilla
Mozilla Foundation Security Advisory 2024-47: CVE-2024-8900
vendor_mozilla·CVSS 7.5
CVE-2024-8900 [HIGH] Mozilla Foundation Security Advisory 2024-47: CVE-2024-8900
Mozilla Foundation Security Advisory 2024-47
CVE: CVE-2024-8900
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 128.3
Mozilla
Mozilla Foundation Security Advisory 2024-49: CVE-2024-8900
vendor_mozilla·CVSS 7.5
CVE-2024-8900 [HIGH] Mozilla Foundation Security Advisory 2024-49: CVE-2024-8900
Mozilla Foundation Security Advisory 2024-49
CVE: CVE-2024-8900
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 128.3
Mozilla
Mozilla Foundation Security Advisory 2024-33: CVE-2024-8900
vendor_mozilla·CVSS 7.5
CVE-2024-8900 [HIGH] Mozilla Foundation Security Advisory 2024-33: CVE-2024-8900
Mozilla Foundation Security Advisory 2024-33
CVE: CVE-2024-8900
Product: Firefox
Impact: low
Fixed in: Firefox 129
No detection rules found.
No public exploits indexed.
2024-09-17
Published