CVE-2024-10462: High severity thunderbird vulnerability
Published Oct 29, 2024
·Updated
Last updated 6 November 2024
Other sources
Truncation of a long URL could have allowed origin spoofing in a permission prompt.
— Mozilla
Affected Software
11 affected componentsFixes available
debian/firefox
132.0.1-1
debian/firefox-esr<=115.14.0esr-1~deb11u1, <=115.14.0esr-1~deb12u1, <=128.3.1esr-2
128.4.0esr-1~deb11u1128.4.0esr-1~deb12u1128.4.0esr-1
debian/thunderbird<=1:115.12.0-1~deb11u1, <=1:115.12.0-1~deb12u1
1:128.4.0esr-1~deb11u11:128.4.0esr-1~deb12u11:128.4.0esr-11:128.4.2esr-1
Mozilla Thunderbird<128.4
128.4
Mozilla Thunderbird<132
132
Mozilla Firefox<128.4.0
Mozilla Firefox<132.0
Mozilla Thunderbird<128.4.0
Mozilla Thunderbird>=129.0<132.0
Mozilla Firefox<132
132
Mozilla Firefox ESR<128.4
128.4
Event History
Oct 29, 2024
CVE Published
via Mozilla·12:00 AM
CVE Published
via MITRE·12:19 PM
Data Sourced
via MITRE·12:19 PM
DescriptionWeakness
Data Sourced
via Red Hat·01:02 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Nov 8, 2024
Data Sourced
via Ubuntu·12:21 PM
RemedyDescriptionSeverityAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2024-10462?
CVE-2024-10462 is considered to have a medium severity level due to its potential for origin spoofing.
2
How do I fix CVE-2024-10462?
To fix CVE-2024-10462, update Firefox to version 132 or later, and Thunderbird to version 132 or later.
3
Which software is affected by CVE-2024-10462?
CVE-2024-10462 affects Firefox versions below 132, Firefox ESR versions below 128.4, and Thunderbird versions below 128.4.
4
What type of vulnerability is CVE-2024-10462?
CVE-2024-10462 is a vulnerability that can lead to origin spoofing through truncation of long URLs in permission prompts.
5
Are there any known exploits for CVE-2024-10462?
As of now, there are no publicly disclosed exploits for CVE-2024-10462.