CVE-2024-6612

CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened. This vulnerability affects Firefox < 128 and Thunderbird < 128.
Configurations

No configuration.

History

21 Nov 2024, 09:49

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1880374 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1880374 -
References () https://www.mozilla.org/security/advisories/mfsa2024-29/ - () https://www.mozilla.org/security/advisories/mfsa2024-29/ -
References () https://www.mozilla.org/security/advisories/mfsa2024-32/ - () https://www.mozilla.org/security/advisories/mfsa2024-32/ -

16 Jul 2024, 18:15

Type Values Removed Values Added
References
  • () https://www.mozilla.org/security/advisories/mfsa2024-32/ -
Summary (en) CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened. This vulnerability affects Firefox < 128. (en) CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened. This vulnerability affects Firefox < 128 and Thunderbird < 128.

11 Jul 2024, 15:06

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-200
Summary
  • (es) Las infracciones de CSP generaron enlaces en la pestaña de la consola de las herramientas de desarrollador, que apuntaban al recurso infractor. Esto provocó una captación previa de DNS que filtró que se había producido una infracción de CSP. Esta vulnerabilidad afecta a Firefox &lt; 128.

09 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 15:15

Updated : 2024-11-21 09:49


NVD link : CVE-2024-6612

Mitre link : CVE-2024-6612

CVE.ORG link : CVE-2024-6612


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor