CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened. This vulnerability affects Firefox < 128 and Thunderbird < 128.
History

Fri, 04 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla
Mozilla firefox
Mozilla thunderbird

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2024-07-09T14:26:00.305Z

Updated: 2024-09-12T15:48:05.076Z

Reserved: 2024-07-09T14:12:57.433Z

Link: CVE-2024-6612

cve-icon Vulnrichment

Updated: 2024-08-01T21:41:04.060Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-09T15:15:13.107

Modified: 2025-04-04T14:42:13.783

Link: CVE-2024-6612

cve-icon Redhat

No data.