CVE-2024-9394: XSS
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the resource://devtools origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
Other sources
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the resource://devtools origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-9394?
CVE-2024-9394 has been classified as a moderate severity vulnerability.
How do I fix CVE-2024-9394?
To remediate CVE-2024-9394, update your Mozilla Firefox or Thunderbird to the latest patched version.
What products are affected by CVE-2024-9394?
CVE-2024-9394 affects multiple versions of Mozilla Firefox ESR, Firefox, and Thunderbird.
What type of vulnerability is CVE-2024-9394?
CVE-2024-9394 is a cross-origin resource sharing vulnerability that enables arbitrary JavaScript execution.
Is there a workaround for CVE-2024-9394?
Currently, the best approach to mitigate CVE-2024-9394 is to upgrade to the latest version of the affected software.