CVE-2024-2609

MEDIUM

Firefox <124, Firefox ESR <115.10, Thunderbird <115.10 - CSRF

Title source: llm
STIX 2.1

Description

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.

Scores

CVSS v3 6.1
EPSS 0.0103
EPSS Percentile 77.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-356
Status published
Products (4)
debian/debian_linux 10.0
mozilla/firefox < 115.10.0
mozilla/firefox < 124.0
mozilla/thunderbird < 115.10.0
Published Mar 19, 2024
Tracked Since Feb 18, 2026