CVE-2024-9393: High severity thunderbird vulnerability
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the resource://pdf.js origin. This could allow them to access cross-origin PDF content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
Other sources
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the resource://pdf.js origin. This could allow them to access cross-origin PDF content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-9393?
CVE-2024-9393 is classified as a significant security vulnerability due to the potential for arbitrary JavaScript execution.
How do I fix CVE-2024-9393?
To fix CVE-2024-9393, update affected Mozilla products such as Firefox ESR to version 128.3 or higher and Thunderbird to version 131 or higher.
Which versions are affected by CVE-2024-9393?
CVE-2024-9393 affects Mozilla Firefox ESR versions up to 128.3, Thunderbird versions up to 131, and other specified earlier versions.
What is the impact of CVE-2024-9393 on sensitive data?
CVE-2024-9393 allows attackers to access cross-origin PDF content, posing risks to sensitive data within those documents.
Is site isolation effective against CVE-2024-9393?
Site Isolation limits CVE-2024-9393's impact by confining access to 'same site' documents on desktop clients.