CVE-2024-5698: Medium severity Mozilla Firefox vulnerability
By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 131.0.3-1 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 127
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-5698?
CVE-2024-5698 is rated as a moderate vulnerability due to its potential for user confusion and spoofing attacks.
How do I fix CVE-2024-5698?
To fix CVE-2024-5698, update Mozilla Firefox to version 131.0.3-1 or higher.
What products are affected by CVE-2024-5698?
CVE-2024-5698 affects Mozilla Firefox versions up to 127 and the corresponding Debian package.
What can an attacker do with CVE-2024-5698?
An attacker can manipulate the fullscreen feature to overlay a text box over the address bar, leading to spoofing attempts.
When was CVE-2024-5698 discovered?
CVE-2024-5698 was publicly reported in 2024.