CVE-2024-32986
Last modified
CVE-2024-32986 is a critical-severity vulnerability rated 9.6/10 on the CVSS scale. PWAsForFirefox is a tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox. Due to improper sanitization of web app properties (such as name, description, shortcuts), web apps were able to inject additional lines into XDG Desktop Entries (on Linux) and `AppInfo.ini` (on PortableApps.com). EPSS estimates a 0.68% chance of exploitation in the next 30 days.
Description
PWAsForFirefox is a tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox. Due to improper sanitization of web app properties (such as name, description, shortcuts), web apps were able to inject additional lines into XDG Desktop Entries (on Linux) and `AppInfo.ini` (on PortableApps.com). This allowed malicious web apps to introduce keys like `Exec`, which could run arbitrary code when the affected web app was launched. This vulnerability affects all Linux and PortableApps.com users of all PWAsForFirefox versions up to (excluding) 2.12.0. Windows and macOS users are not affected. This vulnerability has been fixed in commit `9932d4b` which has been included in release in v2.12.0. The main fix is implemented in the native part, but the extension also contains additional fixes. All Linux and PortableApps.com users are advised to update to this version as soon as possible. It is also recommended for Windows and macOS users to update to this version, as it contains additional fixes related to properties sanitization. There are no known workarounds for this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-32986?
How severe is CVE-2024-32986?
How do I fix CVE-2024-32986?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-32980Spin is the developer tool for building and running serverle…9.1
- CVE-2024-32981Silverstripe framework is the PHP framework forming the base…5.4
- CVE-2024-32982Litestar and Starlite is an Asynchronous Server Gateway Inte…8.2
- CVE-2024-32983Misskey is an open source, decentralized microblogging platf…7.5
- CVE-2024-32984Yamux is a stream multiplexer over reliable, ordered connect…7.5
- CVE-2024-32985Stellar-core is a reference implementation for the peer-to-p…5.9
- CVE-2024-32987Microsoft SharePoint Server Information Disclosure Vulnerabi…7.5
- CVE-2024-32988'OfferBox' App for Android versions 2.0.0 to 2.3.17 and 'Off…7.5
- CVE-2024-32989Insufficient verification vulnerability in the system sharin…7.5
- CVE-2024-3299Out-Of-Bounds Write, Use of Uninitialized Resource and Use-A…7.8
- CVE-2024-32990Permission verification vulnerability in the system sharing …7.5
- CVE-2024-32991Permission verification vulnerability in the wpa_supplicant …9.8
Are you affected by CVE-2024-32986?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
