CVE-2024-4128
CVSS V2 None
CVSS V3 None
Description
This vulnerability was a potential CSRF attack. When running the Firebase emulator suite, there is an export endpoint that is used normally to export data from running emulators. If a user was running the emulator and navigated to a malicious website with the exploit on a browser that allowed calls to localhost (ie Chrome before v94), the website could exfiltrate emulator data. We recommend upgrading past version 13.6.0 or commit 068a2b08dc308c7ab4b569617f5fc8821237e3a0 https://github.com/firebase/firebase-tools/commit/068a2b08dc308c7ab4b569617f5fc8821237e3a0
Overview
- CVE ID
- CVE-2024-4128
- Assigner
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-05-02T13:22:50.829Z
- Last Modified Date
- 2024-06-04T17:56:00.050Z
Weakness Enumerations
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-4128 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4128 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-23 21:55:21 | Added to TrackCVE |