REDHAT-BUG-2368755: Medium severity firefox vulnerability
Published May 27, 2025
·Updated
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11.
Affected Software
2 affected components
Mozilla Firefox<139
Mozilla Firefox ESR<128.11
Event History
May 27, 2025
Data Sourced
via Red Hat·01:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2368755?
The severity of REDHAT-BUG-2368755 is classified as medium due to the potential for XS-Leaks attacks.
2
How do I fix REDHAT-BUG-2368755?
To fix REDHAT-BUG-2368755, update Firefox to version 139 or later, or Firefox ESR to version 128.11 or later.
3
What versions of Firefox are affected by REDHAT-BUG-2368755?
Firefox versions prior to 139 and Firefox ESR versions prior to 128.11 are affected by REDHAT-BUG-2368755.
4
What type of attack does REDHAT-BUG-2368755 enable?
REDHAT-BUG-2368755 enables XS-Leaks attacks due to information leakage from cross-origin resource events.
5
Is there a workaround for REDHAT-BUG-2368755?
Currently, the best workaround for REDHAT-BUG-2368755 is to upgrade to the latest versions of affected Firefox browsers.