CVE-2024-10461: XSS
In multipart/x-mixed-replace responses, Content-Disposition: attachment in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Other sources
In multipart/x-mixed-replace responses, Content-Disposition: attachment in the response header was not respected and did not force a download, which could allow XSS attacks.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-10461?
CVE-2024-10461 is considered a medium severity vulnerability due to its potential to allow XSS attacks.
How do I fix CVE-2024-10461?
To fix CVE-2024-10461, update affected software to Mozilla Firefox version 132 or Thunderbird version 132, and Firefox ESR and Thunderbird versions 128.4.
Which versions are affected by CVE-2024-10461?
CVE-2024-10461 affects Firefox versions below 132, Firefox ESR versions below 128.4, and Thunderbird versions below 132.
What types of attacks can exploit CVE-2024-10461?
CVE-2024-10461 can be exploited for cross-site scripting (XSS) attacks due to improper handling of response headers.
Who is affected by CVE-2024-10461?
Users of Mozilla Firefox, Firefox ESR, and Thunderbird prior to the specified safe versions are at risk from CVE-2024-10461.