CVE-2024-10474 Vulnerability Details

  /     /     /  

CVE-2024-10474 Metadata Quick Info

CVE Published: 29/10/2024 | CVE Updated: 29/10/2024 | CVE Year: 2024
Source: mozilla | Vendor: Mozilla | Product: Focus for iOS
Status : PUBLISHED

CVE-2024-10474 Description

Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing some URL safety checks This vulnerability affects Focus for iOS < 132.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Don t allow web content to open firefox-focus URLs
Source: Mozilla

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).