CVE-2024-1551: Medium severity Mozilla Thunderbird vulnerability
Last updated 24 July 2024
Other sources
Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-Cookie response headers that would have been honored by the browser.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 115.8 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 123 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.8 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 137.0.2-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 128.9.0esr-1~deb11u1Fixed in 128.8.0esr-1~deb12u1Fixed in 128.9.0esr-1~deb12u1Fixed in 128.9.0esr-2 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:128.9.0esr-1~deb11u1Fixed in 1:128.8.0esr-1~deb12u1Fixed in 1:128.9.0esr-1~deb12u1Fixed in 1:128.9.0esr-1 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 115.8 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 115.8 - Upgrade
Upgrade
firefoxto a version that resolves this vulnerability.Fixed in 123 - Upgrade
Upgrade
firefox ESRto a version that resolves this vulnerability.Fixed in 115.8 - Upgrade
Upgrade
thunderbirdto a version that resolves this vulnerability.Fixed in 115.8
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-1551?
CVE-2024-1551 is considered a moderate severity vulnerability due to the potential for cookie injection through manipulated multipart HTTP responses.
How do I fix CVE-2024-1551?
To fix CVE-2024-1551, update your affected software to the latest versions provided by the vendor.
What products are affected by CVE-2024-1551?
CVE-2024-1551 affects Mozilla Firefox versions up to 123, Thunderbird versions up to 115.8, and Firefox ESR versions up to 115.8.
What can an attacker do with CVE-2024-1551?
An attacker can exploit CVE-2024-1551 to inject malicious Set-Cookie headers into legitimate multipart HTTP responses.
Is there a workaround for CVE-2024-1551?
No specific workaround is recommended for CVE-2024-1551; applying the latest software updates is the best measure.