CVE-2024-1555: High severity Mozilla Firefox vulnerability
Last updated 24 July 2024
Other sources
When opening a website using the firefox:// protocol handler, SameSite cookies were not properly respected. This vulnerability affects Firefox < 123.
— NVD
When opening a website using the firefox:// protocol handler, SameSite cookies were not properly respected.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 123 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 137.0.2-1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-1555?
CVE-2024-1555 has been classified as a moderate severity vulnerability due to the potential for cookie mismanagement.
How do I fix CVE-2024-1555?
To fix CVE-2024-1555, users should upgrade to Mozilla Firefox version 123 or above.
Which versions of Firefox are affected by CVE-2024-1555?
CVE-2024-1555 affects all versions of Firefox prior to version 123.
Does CVE-2024-1555 affect Firefox on Debian systems?
Yes, Debian systems using Firefox versions below 134.0.2-2 are also affected by CVE-2024-1555.
What are the implications of CVE-2024-1555 for web developers?
Web developers should be aware that CVE-2024-1555 may lead to unexpected behavior concerning SameSite cookie attributes.