First published: Tue Oct 01 2024(Updated: )
A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <131 | |
Firefox ESR | <128.3 | |
Thunderbird | <128.3<131 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2315949 is assessed as moderate due to the potential for clickjacking attacks.
To fix REDHAT-BUG-2315949, update to Firefox version 131 or newer, Firefox ESR version 128.3 or newer, or Thunderbird version 131 or newer.
Users of Firefox versions earlier than 131, Firefox ESR versions earlier than 128.3, and Thunderbird versions earlier than 131 are affected by REDHAT-BUG-2315949.
REDHAT-BUG-2315949 is a clickjacking vulnerability that allows an attacker to potentially trick users into granting permissions.
The vulnerability identified as REDHAT-BUG-2315949 was reported in 2024.