alpine · CVE-2024-9397

Quick triage

Priority: not assigned Published: Updated:

View at Official alpine advisory, NVD, CVE.org · CVE detail

Freshness: no update timestamp found; verify against the upstream OS advisory manually.

Tracker summary

CVE-2024-9397: 3 source package rows (firefox, firefox-esr, thunderbird); 334 state rows across 3 repos (3.20-community, 3.22-community, edge-community); fixed 0, open 334.

Description:

A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

cvelogic Threat Intelligence