NA

CVE-2024-4769

Published: 14/05/2024 Updated: 14/05/2024

Vulnerability Summary

When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

Vendor Advisories

Mozilla Foundation Security Advisory 2024-22 Security Vulnerabilities fixed in Firefox ESR 11511 Announced May 14, 2024 Impact high Products Firefox ESR Fixed in Firefox ESR 11511 ...
Mozilla Foundation Security Advisory 2024-21 Security Vulnerabilities fixed in Firefox 126 Announced May 14, 2024 Impact high Products Firefox Fixed in Firefox 126 ...
Mozilla Foundation Security Advisory 2024-23 Security Vulnerabilities fixed in Thunderbird 11511 Announced May 15, 2024 Impact high Products Thunderbird Fixed in Thunderbird 11511 ...