Vulnerability CVE-2024-1554: Information

Description

The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Under the correct circumstances, an attacker may have been able to poison the local browser cache by priming it with a `fetch()` response controlled by the additional headers. Upon navigation to the same URL, the user would see the cached response instead of the expected response. This vulnerability affects Firefox < 123.

Published: Feb. 20, 2024
Modified: Feb. 20, 2024

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
firefoxsisyphus123.0-alt1126.0.1-alt1ALT-PU-2024-2933-1341362Fixed
firefoxsisyphus_riscv64123.0-alt0.port126.0-alt0.portALT-PU-2024-3300-1-Fixed
firefoxsisyphus_loongarch64123.0-alt1.0.port126.0-alt1.0.portALT-PU-2024-3000-1-Fixed
firefoxp11123.0-alt1126.0.1-alt1ALT-PU-2024-2933-1341362Fixed

References to Advisories, Solutions, and Tools