CVE-2024-11694 Information
Nov 27, 2024
cve
Description
Enhanced Tracking Protection’s Strict mode may have inadvertently allowed a CSP frame-src bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading as legitimate content. This vulnerability affects Firefox < 133 Firefox ESR < 128.5 Firefox ESR < 115.18 Thunderbird < 133 and Thunderbird < 128.5.
Reference
https://bugzilla.mozilla.org/show_bug.cgi?id=1924167 https://www.mozilla.org/security/advisories/mfsa2024-63/ https://www.mozilla.org/security/advisories/mfsa2024-64/ https://www.mozilla.org/security/advisories/mfsa2024-65/ https://www.mozilla.org/security/advisories/mfsa2024-67/ https://www.mozilla.org/security/advisories/mfsa2024-68/
Share on: