CVE-2024-5698: Medium severity firefox vulnerability
Published Jun 11, 2024
·Updated
By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks.
Affected Software
3 affected componentsFixes available
debian/firefox
131.0.3-1
Mozilla Firefox<127
127
Mozilla Firefox<127
Event History
Jun 11, 2024
CVE Published
via Mozilla·12:00 AM
CVE Published
via MITRE·12:40 PM
Data Sourced
via MITRE·12:40 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Jul 3, 2024
Data Sourced
via Launchpad·08:12 AM
Description
Sep 17, 2024
Data Sourced
via Ubuntu·08:20 AM
RemedyDescriptionSeverityAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2024-5698?
CVE-2024-5698 is rated as a moderate vulnerability due to its potential for user confusion and spoofing attacks.
2
How do I fix CVE-2024-5698?
To fix CVE-2024-5698, update Mozilla Firefox to version 131.0.3-1 or higher.
3
What products are affected by CVE-2024-5698?
CVE-2024-5698 affects Mozilla Firefox versions up to 127 and the corresponding Debian package.
4
What can an attacker do with CVE-2024-5698?
An attacker can manipulate the fullscreen feature to overlay a text box over the address bar, leading to spoofing attempts.
5
When was CVE-2024-5698 discovered?
CVE-2024-5698 was publicly reported in 2024.