CVE-2024-0747
Mozilla: Bypass of Content Security Policy when directive unsafe-inline was set
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
Cuando una página principal cargaba una secundaria en un iframe con "unsafe-inline", la política de seguridad de contenido principal podría haber anulado la política de seguridad de contenido secundaria. Esta vulnerabilidad afecta a Firefox < 122, Firefox ESR < 115.7 y Thunderbird < 115.7.
The Mozilla Foundation Security Advisory describes this flaw as:
When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-01-19 CVE Reserved
- 2024-01-23 CVE Published
- 2024-02-08 EPSS Updated
- 2024-10-18 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-1021: Improper Restriction of Rendered UI Layers or Frames
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2024/01/msg00015.html | Mailing List | |
https://lists.debian.org/debian-lts-announce/2024/01/msg00022.html | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.mozilla.org/security/advisories/mfsa2024-01 | 2024-02-02 | |
https://www.mozilla.org/security/advisories/mfsa2024-02 | 2024-02-02 | |
https://www.mozilla.org/security/advisories/mfsa2024-04 | 2024-02-02 | |
https://access.redhat.com/security/cve/CVE-2024-0747 | 2024-01-30 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2259929 | 2024-01-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | < 122.0 Search vendor "Mozilla" for product "Firefox" and version " < 122.0" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Esr Search vendor "Mozilla" for product "Firefox Esr" | < 115.7 Search vendor "Mozilla" for product "Firefox Esr" and version " < 115.7" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | < 115.7 Search vendor "Mozilla" for product "Thunderbird" and version " < 115.7" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
|