CVE-2024-4769: Medium severity Mozilla Thunderbird vulnerability
Last updated 24 July 2024
Other sources
When importing resources using Web Workers, error messages would distinguish the difference between application/javascript responses and non-script responses. This could have been abused to learn information cross-origin.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2024-22/#CVE-2024-4769
— Red Hat
When importing resources using Web Workers, error messages would distinguish the difference between application/javascript responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
— NVD
When importing resources using Web Workers, error messages would distinguish the difference between application/javascript responses and non-script responses. This could have been abused to learn information cross-origin.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 130.0.1-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 115.15.0esr-1~deb11u1Fixed in 115.14.0esr-1~deb12u1Fixed in 115.15.0esr-1~deb12u1Fixed in 115.15.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:115.15.0-1~deb11u1Fixed in 1:115.12.0-1~deb12u1Fixed in 1:115.15.0-1~deb12u1Fixed in 1:128.2.0esr-1Fixed in 1:128.2.1esr-1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 115.11 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 126 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.11 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 115.11 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 115.11
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-4769?
CVE-2024-4769 has a medium severity rating due to its potential for cross-origin information disclosure.
How do I fix CVE-2024-4769?
To remediate CVE-2024-4769, users should update to the latest versions of affected software, such as Firefox ESR 115.11 or Thunderbird 115.11.
Which versions are affected by CVE-2024-4769?
CVE-2024-4769 affects Mozilla Firefox up to version 126 and Mozilla Thunderbird up to version 115.11.
Is CVE-2024-4769 exploitable in specific environments?
CVE-2024-4769 can be exploited in environments where cross-origin resource sharing is enabled.
What can attackers gain from exploiting CVE-2024-4769?
Attackers exploiting CVE-2024-4769 may access sensitive information through cross-origin resources due to improper error handling.