CVE-2024-9397: Medium severity Mozilla Thunderbird vulnerability
A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-9397?
The severity of CVE-2024-9397 is considered moderate due to the potential for user password compromise through clickjacking.
How do I fix CVE-2024-9397?
To fix CVE-2024-9397, update Mozilla Thunderbird, Firefox, or Firefox ESR to the latest versions as specified in the official advisories.
Which versions are affected by CVE-2024-9397?
CVE-2024-9397 affects Mozilla Thunderbird versions up to 131, Firefox versions up to 131, and Firefox ESR versions up to 128.3.
What is clickjacking in relation to CVE-2024-9397?
Clickjacking is a technique that tricks users into clicking on something different from what they perceive, potentially leading to unauthorized access.
Can CVE-2024-9397 impact user privacy?
Yes, CVE-2024-9397 can impact user privacy by allowing attackers to trick users into granting permissions without their knowledge.