CVE-2024-9398: Medium severity thunderbird vulnerability
By checking the result of calls to window.open with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
Other sources
By checking the result of calls to window.open with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-9398?
CVE-2024-9398 is considered a moderate severity vulnerability due to its potential to expose installed applications through protocol handlers.
How do I fix CVE-2024-9398?
To fix CVE-2024-9398, update Firefox to version 131 or later and Thunderbird to version 128.3 or later.
Which versions are affected by CVE-2024-9398?
CVE-2024-9398 affects Firefox versions below 131, Firefox ESR versions below 128.3, and Thunderbird versions below 128.3.
Who is affected by CVE-2024-9398?
Users of Firefox, Firefox ESR, and Thunderbird versions below the remedial versions are affected by CVE-2024-9398.
What type of vulnerability is CVE-2024-9398?
CVE-2024-9398 is a URL handler vulnerability that can reveal information about the applications installed on a user's system.