CVE-2024-1554

CVSS v3.1 9.8 (Critical)
98% Progress
EPSS 0.04 % (10th)
0.04% Progress
Advisories 3
NVD Status Awaiting Analysis

The fetch() API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers fetch() may contain. Under the correct circumstances, an attacker may have been able to poison the local browser cache by priming it with a fetch() response controlled by the additional headers. Upon navigation to the same URL, the user would see the cached response instead of the expected response. This vulnerability affects Firefox < 123.

Weaknesses
CWE-345
Insufficient Verification of Data Authenticity
CVE Status
PUBLISHED
NVD Status
Awaiting Analysis
CNA
Mozilla Corporation
Published Date
2024-02-20 14:15:08
(6 months ago)
Updated Date
2024-08-20 20:35:08
(3 weeks ago)
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...