CVE-2024-2610: Code Injection
Last updated 24 July 2024
Other sources
Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-2610?
CVE-2024-2610 is classified as a high-severity vulnerability due to its potential to bypass strict content security policies.
How do I fix CVE-2024-2610?
To fix CVE-2024-2610, update affected software to the latest versions specified in the vendor's advisory.
Which software is affected by CVE-2024-2610?
CVE-2024-2610 affects Mozilla Firefox versions up to 124, Firefox ESR versions up to 115.9, and Thunderbird versions up to 115.9.
Can CVE-2024-2610 lead to data theft?
Yes, CVE-2024-2610 can potentially allow attackers to steal nonce values, leading to data theft.
Is CVE-2024-2610 associated with markup injection?
Yes, CVE-2024-2610 is a markup injection vulnerability that enables attackers to exploit nonce values.