SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-8382

Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events.

HIGH 8.8EPSS 0.60%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces would not be able to use them with elevated privileges, but their presence would indicate certain browser features had been used, such as when a user opened the Dev Tools console. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
0.60% probability · 47th percentile
CISA KEV
Not listed
Weakness
CWE-273
Affected
mozilla/firefox · mozilla/firefox esr
Source
security@mozilla.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.