CVE-2024-6610: Form validation popups could block exiting full-screen mode
Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 131.0.2-2 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 128 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 128 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 128 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 128
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-6610?
CVE-2024-6610 has been classified as a medium severity vulnerability.
How do I fix CVE-2024-6610?
To mitigate CVE-2024-6610, update to Mozilla Firefox or Thunderbird version 131.0.2-2 or later.
What are the affected versions of CVE-2024-6610?
CVE-2024-6610 affects Mozilla Firefox and Thunderbird versions prior to 128.0.
What impact does CVE-2024-6610 have on users?
CVE-2024-6610 may prevent users from exiting full-screen mode due to spammed form validation messages.
Is there a workaround for CVE-2024-6610?
Currently, there is no effective workaround for CVE-2024-6610 aside from updating to a patched version.