Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
The product does not properly verify that the source of data or communication is valid.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Firefox | Mozilla | * | 153.4.0 (excluding) |
| Firefox | Mozilla | 154.0.0 (including) | 157.0.0 (excluding) |
| Thunderbird | Mozilla | * | 153.4.0 (excluding) |
| Thunderbird | Mozilla | 154.0 (including) | 157.0 (excluding) |
| Mozjs102 | Ubuntu | esm-apps/noble | * |
| Mozjs102 | Ubuntu | jammy | * |
| Mozjs102 | Ubuntu | noble | * |
| Mozjs115 | Ubuntu | noble | * |
| Mozjs52 | Ubuntu | esm-apps/focal | * |
| Mozjs52 | Ubuntu | esm-infra/bionic | * |
| Mozjs68 | Ubuntu | esm-infra/focal | * |
| Mozjs78 | Ubuntu | esm-apps/jammy | * |
| Mozjs78 | Ubuntu | jammy | * |
| Mozjs91 | Ubuntu | jammy | * |
| Thunderbird | Ubuntu | jammy | * |