First published: Tue Oct 01 2024(Updated: )
By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <131 | |
Firefox ESR | <128.3 | |
Thunderbird | <128.3<131 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-2315952 is considered a medium severity vulnerability due to its potential to allow an attacker to determine installed protocol handlers.
REDHAT-BUG-2315952 affects Firefox versions below 131, Firefox ESR versions below 128.3, and Thunderbird versions below 128.3.
To fix REDHAT-BUG-2315952, update your Firefox, Firefox ESR, or Thunderbird to the latest version that is no longer affected.
REDHAT-BUG-2315952 is a cross-site scripting vulnerability that can expose information about installed applications.
While the best solution is to update the software, temporarily disabling protocol handlers may serve as a workaround until updates are applied.