When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
2024-05-14T18:15:14.297
2025-04-01T17:46:33.833
Analyzed
CVSSv3.1: 5.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mozilla | firefox | < 115.11.0 | Yes |
Application | mozilla | firefox | < 126.0 | Yes |
Application | mozilla | thunderbird | < 115.11.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |