CVE-2024-10458: High severity thunderbird vulnerability
A permission leak could have occurred from a trusted site to an untrusted site via embed or object elements. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
Other sources
A permission leak could have occurred from a trusted site to an untrusted site via embed or object elements.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-10458?
CVE-2024-10458 is a permission leak vulnerability that can potentially allow access from a trusted site to an untrusted site.
How do I fix CVE-2024-10458?
To fix CVE-2024-10458, update to Firefox version 132, Thunderbird version 132, or Firefox ESR version 115.17 or higher.
Which versions are affected by CVE-2024-10458?
CVE-2024-10458 affects Firefox versions below 132, Firefox ESR versions below 128.4 and 115.17, as well as Thunderbird versions below 132.
What products are impacted by CVE-2024-10458?
CVE-2024-10458 impacts Mozilla Firefox, Mozilla Firefox ESR, and Mozilla Thunderbird across the specified affected versions.
Is CVE-2024-10458 exploitable?
Yes, CVE-2024-10458 is exploitable due to the permission leak between trusted and untrusted sites.