CVE-2024-6611: Incorrect handling of SameSite cookies
A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 131.0.2-2 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 128 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 128
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-6611?
CVE-2024-6611 has a moderate severity rating due to its potential to expose sensitive information through improper cookie handling.
How do I fix CVE-2024-6611?
To mitigate CVE-2024-6611, update your Mozilla Firefox or Thunderbird to version 128 or later.
What versions are affected by CVE-2024-6611?
CVE-2024-6611 affects Mozilla Firefox versions prior to 128 and Thunderbird versions prior to 128.
What type of vulnerability is CVE-2024-6611?
CVE-2024-6611 is a cross-site scripting vulnerability stemming from improper handling of SameSite cookies in nested iframes.
Is there a patch available for CVE-2024-6611?
Yes, a patch is included in the updates for Mozilla Firefox and Thunderbird version 128 and above.