A security vulnerability in Firefox allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins. This vulnerability affects Firefox < 138 and Thunderbird < 138.
History

Tue, 29 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Apr 2025 13:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability in Firefox allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins. This vulnerability affects Firefox < 138 and Thunderbird < 138.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2025-04-29T13:13:43.684Z

Updated: 2025-04-29T15:51:08.615Z

Reserved: 2025-04-29T13:13:43.020Z

Link: CVE-2025-4088

cve-icon Vulnrichment

Updated: 2025-04-29T15:50:59.333Z

cve-icon NVD

Status : Received

Published: 2025-04-29T14:15:35.450

Modified: 2025-04-29T16:15:39.153

Link: CVE-2025-4088

cve-icon Redhat

No data.