CVE-2024-0747: Medium severity thunderbird vulnerability
Last updated 24 July 2024
Other sources
When a parent page loaded a child in an iframe with unsafe-inline, the parent Content Security Policy could have overridden the child Content Security Policy.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2024-02/#CVE-2024-0747
— Red Hat
When a parent page loaded a child in an iframe with unsafe-inline, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
— Launchpad
When a parent page loaded a child in an iframe with unsafe-inline, the parent Content Security Policy could have overridden the child Content Security Policy.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-0747?
CVE-2024-0747 has been classified as a moderate severity vulnerability due to its impact on content security policies.
How do I fix CVE-2024-0747?
To fix CVE-2024-0747, update to the latest versions of affected products such as Thunderbird or Firefox as specified in the vulnerability details.
What products are affected by CVE-2024-0747?
CVE-2024-0747 affects Mozilla Thunderbird versions below 115.7, Mozilla Firefox ESR versions below 115.7, and various versions of Firefox up to 122.
What are the consequences of CVE-2024-0747?
The consequence of CVE-2024-0747 is that the parent Content Security Policy may override the child Content Security Policy, leading to potential security risks.
Is there a workaround for CVE-2024-0747?
There is no definitive workaround for CVE-2024-0747; updating to a secure version of the software is recommended.