First published: Tue May 14 2024(Updated: )
If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. External Reference: <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2024-22/#CVE-2024-4767">https://www.mozilla.org/en-US/security/advisories/mfsa2024-22/#CVE-2024-4767</a>
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/firefox | <115.11 | 115.11 |
redhat/thunderbird | <115.11 | 115.11 |
debian/firefox | 130.0.1-1 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 115.15.0esr-1~deb11u1 115.14.0esr-1~deb12u1 115.15.0esr-1~deb12u1 115.15.0esr-1 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:115.15.0-1~deb11u1 1:115.12.0-1~deb12u1 1:115.15.0-1~deb12u1 1:128.2.0esr-1 1:128.2.1esr-1 | |
Thunderbird | <115.11 | 115.11 |
Firefox | <126 | 126 |
Firefox ESR | <115.11 | 115.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-4767 has a moderate severity rating due to the potential risk of unauthorized access to IndexedDB files.
To mitigate CVE-2024-4767, update your Firefox or Thunderbird to versions 115.11 or above.
CVE-2024-4767 affects Mozilla Firefox ESR prior to 115.11, Mozilla Thunderbird prior to 115.11, and regular Firefox prior to version 126.
Yes, if 'browser.privatebrowsing.autostart' is enabled, CVE-2024-4767 can lead to IndexedDB files not being deleted properly.
CVE-2024-4767 is not considered critical, but it poses a security risk if sensitive data remains accessible after a private browsing session.