CVE-2024-4768: Medium severity Mozilla Thunderbird vulnerability
A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 130.0.1-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 115.15.0esr-1~deb11u1Fixed in 115.14.0esr-1~deb12u1Fixed in 115.15.0esr-1~deb12u1Fixed in 115.15.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:115.15.0-1~deb11u1Fixed in 1:115.12.0-1~deb12u1Fixed in 1:115.15.0-1~deb12u1Fixed in 1:128.2.0esr-1Fixed in 1:128.2.1esr-1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 115.11 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 126 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.11 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 115.11 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 115.11
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-4768?
CVE-2024-4768 has a high severity rating due to the potential for user permission spoofing by attackers.
How do I fix CVE-2024-4768?
To fix CVE-2024-4768, update Mozilla Firefox ESR to version 115.11 or later, Thunderbird to version 115.11 or later, and Firefox to version 126 or later.
What software is affected by CVE-2024-4768?
CVE-2024-4768 affects Mozilla Firefox ESR, Thunderbird, and standard Firefox versions prior to their respective updates.
Can CVE-2024-4768 be exploited remotely?
Yes, CVE-2024-4768 can potentially be exploited remotely if users are tricked into granting permissions.
Is there a known exploit for CVE-2024-4768?
As of now, there are no publicly disclosed exploits specifically targeting CVE-2024-4768, but the vulnerability poses a significant risk.