It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
2024-08-06T13:15:57.420
2024-08-12T16:07:19.537
Analyzed
CVSSv3.1: 8.1 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mozilla | firefox | < 129.0 | Yes |
| Application | mozilla | firefox_esr | < 115.14.0 | Yes |
| Application | mozilla | firefox_esr | 128.0 | Yes |
| Application | mozilla | thunderbird | < 115.14.0 | Yes |
| Application | mozilla | thunderbird | 128.0.1 | Yes |