Description
If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The triggering principal is used to calculate many values, including the `Referer` and `Sec-*` headers, meaning there is the potential for incorrect security checks within the browser in addition to incorrect or misleading information sent to remote websites.
*This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 127.
*This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 127.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 27 Mar 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla
Mozilla firefox |
|
| CPEs | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mozilla
Mozilla firefox |
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-01T21:18:06.882Z
Reserved: 2024-06-06T15:05:00.457Z
Link: CVE-2024-5687
Updated: 2024-08-01T21:18:06.882Z
Status : Analyzed
Published: 2024-06-11T13:15:50.260
Modified: 2025-03-27T20:13:57.260
Link: CVE-2024-5687
No data.
OpenCVE Enrichment
No data.
Weaknesses