{
	"document": {
	  "aggregate_severity": {
		"namespace": "https://nvd.nist.gov/vuln-metrics/cvss",
		"text": "None"
	  },
	  "category": "csaf_vex",
	  "csaf_version": "2.0",
	  "distribution": {
		"tlp": {
		  "label": "WHITE",
		  "url": "https:/www.first.org/tlp/"
		}
	  },
	  "lang": "en",
	  "notes": [
		{
		  "text": "firefox security update",
		  "category": "general",
		  "title": "Synopsis"
		},
		{
		  "text": "An update for firefox is now available for openEuler-24.03-LTS",
		  "category": "general",
		  "title": "Summary"
		},
		{
		  "text": "Mozilla Firefox is a standalone web browser, designed for standards compliance and performance.  Its functionality can be enhanced via a plethora of extensions.\n\nSecurity Fix(es):\n\nBy tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.(CVE-2024-5691)",
		  "category": "general",
		  "title": "Description"
		},
		{
		  "text": "An update for firefox is now available for openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.",
		  "category": "general",
		  "title": "Topic"
		},
		{
		  "text": "Medium",
		  "category": "general",
		  "title": "Severity"
		},
		{
		  "text": "firefox",
		  "category": "general",
		  "title": "Affected Component"
		}
	  ],
	  "publisher": {
		"issuing_authority": "openEuler security committee",
		"name": "openEuler",
		"namespace": "https://www.openeuler.org",
		"contact_details": "openeuler-security@openeuler.org",
		"category": "vendor"
	  },
	  "references": [
		{
		  "summary": "openEuler-SA-2024-2013",
		  "category": "self",
		  "url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-2013"
		},
		{
		  "summary": "CVE-2024-5691",
		  "category": "self",
		  "url": "https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-5691&packageName=firefox"
		},
		{
		  "summary": "nvd cve",
		  "category": "external",
		  "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5691"
		},
		{
		  "summary": "openEuler-SA-2024-2013 vex file",
		  "category": "self",
		  "url": "https://repo.openeuler.org/security/data/csaf/advisories/2024/csaf-openEuler-SA-2024-2013.json"
		}
	  ],
	  "title": "An update for firefox is now available for openEuler-24.03-LTS",
	  "tracking": {
		"initial_release_date": "2024-08-23T19:58:27+08:00",
		"revision_history": [
		  {
			"date": "2024-08-23T19:58:27+08:00",
			"summary": "Initial",
			"number": "1.0.0"
		  },
		  {
			"date": "2024-08-26T21:45:27+08:00",
			"summary": "final",
			"number": "2.0.0"
		  }
		],
		"generator": {
		  "date": "2024-08-26T21:45:27+08:00",
		  "engine": {
			"name": "openEuler CSAF Tool V1.0"
		  }
		},
		"current_release_date": "2024-08-26T21:45:27+08:00",
		"id": "openEuler-SA-2024-2013",
		"version": "2.0.0",
		"status": "final"
	  }
	},
	"product_tree": {
	  "branches": [
		{
		  "name": "openEuler",
		  "category": "vendor",
		  "branches": [
			{
			  "name": "openEuler",
			  "branches": [
				{
				  "product": {
					"product_identification_helper": {
					  "cpe": "cpe:/a:openEuler:openEuler:24.03-LTS"
					},
					"product_id": "openEuler-24.03-LTS",
					"name": "openEuler-24.03-LTS"
				  },
				  "name": "openEuler-24.03-LTS",
				  "category": "product_version"
				}
			  ],
			  "category": "product_name"
			},
			{
			  "name": "src",
			  "branches": [
				{
				  "product": {
					"product_identification_helper": {
					  "cpe": "cpe:/a:openEuler:openEuler:24.03-LTS"
					},
					"product_id": "firefox-115.14.0-1.oe2403.src.rpm",
					"name": "firefox-115.14.0-1.oe2403.src.rpm"
				  },
				  "name": "firefox-115.14.0-1.oe2403.src.rpm",
				  "category": "product_version"
				}
			  ],
			  "category": "architecture"
			},
			{
			  "name": "x86_64",
			  "branches": [
				{
				  "product": {
					"product_identification_helper": {
					  "cpe": "cpe:/a:openEuler:openEuler:24.03-LTS"
					},
					"product_id": "firefox-115.14.0-1.oe2403.x86_64.rpm",
					"name": "firefox-115.14.0-1.oe2403.x86_64.rpm"
				  },
				  "name": "firefox-115.14.0-1.oe2403.x86_64.rpm",
				  "category": "product_version"
				},
				{
				  "product": {
					"product_identification_helper": {
					  "cpe": "cpe:/a:openEuler:openEuler:24.03-LTS"
					},
					"product_id": "firefox-debuginfo-115.14.0-1.oe2403.x86_64.rpm",
					"name": "firefox-debuginfo-115.14.0-1.oe2403.x86_64.rpm"
				  },
				  "name": "firefox-debuginfo-115.14.0-1.oe2403.x86_64.rpm",
				  "category": "product_version"
				},
				{
				  "product": {
					"product_identification_helper": {
					  "cpe": "cpe:/a:openEuler:openEuler:24.03-LTS"
					},
					"product_id": "firefox-debugsource-115.14.0-1.oe2403.x86_64.rpm",
					"name": "firefox-debugsource-115.14.0-1.oe2403.x86_64.rpm"
				  },
				  "name": "firefox-debugsource-115.14.0-1.oe2403.x86_64.rpm",
				  "category": "product_version"
				}
			  ],
			  "category": "architecture"
			},
			{
			  "name": "aarch64",
			  "branches": [
				{
				  "product": {
					"product_identification_helper": {
					  "cpe": "cpe:/a:openEuler:openEuler:24.03-LTS"
					},
					"product_id": "firefox-115.14.0-1.oe2403.aarch64.rpm",
					"name": "firefox-115.14.0-1.oe2403.aarch64.rpm"
				  },
				  "name": "firefox-115.14.0-1.oe2403.aarch64.rpm",
				  "category": "product_version"
				},
				{
				  "product": {
					"product_identification_helper": {
					  "cpe": "cpe:/a:openEuler:openEuler:24.03-LTS"
					},
					"product_id": "firefox-debuginfo-115.14.0-1.oe2403.aarch64.rpm",
					"name": "firefox-debuginfo-115.14.0-1.oe2403.aarch64.rpm"
				  },
				  "name": "firefox-debuginfo-115.14.0-1.oe2403.aarch64.rpm",
				  "category": "product_version"
				},
				{
				  "product": {
					"product_identification_helper": {
					  "cpe": "cpe:/a:openEuler:openEuler:24.03-LTS"
					},
					"product_id": "firefox-debugsource-115.14.0-1.oe2403.aarch64.rpm",
					"name": "firefox-debugsource-115.14.0-1.oe2403.aarch64.rpm"
				  },
				  "name": "firefox-debugsource-115.14.0-1.oe2403.aarch64.rpm",
				  "category": "product_version"
				}
			  ],
			  "category": "architecture"
			}
		  ]
		}
	  ],
	  "relationships": [
		{
		  "relates_to_product_reference": "openEuler-24.03-LTS",
		  "product_reference": "firefox-115.14.0-1.oe2403.src.rpm",
		  "full_product_name": {
			"product_id": "openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.src",
			"name": "firefox-115.14.0-1.oe2403.src as a component of openEuler-24.03-LTS"
		  },
		  "category": "default_component_of"
		},
		{
		  "relates_to_product_reference": "openEuler-24.03-LTS",
		  "product_reference": "firefox-115.14.0-1.oe2403.x86_64.rpm",
		  "full_product_name": {
			"product_id": "openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.x86_64",
			"name": "firefox-115.14.0-1.oe2403.x86_64 as a component of openEuler-24.03-LTS"
		  },
		  "category": "default_component_of"
		},
		{
		  "relates_to_product_reference": "openEuler-24.03-LTS",
		  "product_reference": "firefox-debuginfo-115.14.0-1.oe2403.x86_64.rpm",
		  "full_product_name": {
			"product_id": "openEuler-24.03-LTS:firefox-debuginfo-115.14.0-1.oe2403.x86_64",
			"name": "firefox-debuginfo-115.14.0-1.oe2403.x86_64 as a component of openEuler-24.03-LTS"
		  },
		  "category": "default_component_of"
		},
		{
		  "relates_to_product_reference": "openEuler-24.03-LTS",
		  "product_reference": "firefox-debugsource-115.14.0-1.oe2403.x86_64.rpm",
		  "full_product_name": {
			"product_id": "openEuler-24.03-LTS:firefox-debugsource-115.14.0-1.oe2403.x86_64",
			"name": "firefox-debugsource-115.14.0-1.oe2403.x86_64 as a component of openEuler-24.03-LTS"
		  },
		  "category": "default_component_of"
		},
		{
		  "relates_to_product_reference": "openEuler-24.03-LTS",
		  "product_reference": "firefox-115.14.0-1.oe2403.aarch64.rpm",
		  "full_product_name": {
			"product_id": "openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.aarch64",
			"name": "firefox-115.14.0-1.oe2403.aarch64 as a component of openEuler-24.03-LTS"
		  },
		  "category": "default_component_of"
		},
		{
		  "relates_to_product_reference": "openEuler-24.03-LTS",
		  "product_reference": "firefox-debuginfo-115.14.0-1.oe2403.aarch64.rpm",
		  "full_product_name": {
			"product_id": "openEuler-24.03-LTS:firefox-debuginfo-115.14.0-1.oe2403.aarch64",
			"name": "firefox-debuginfo-115.14.0-1.oe2403.aarch64 as a component of openEuler-24.03-LTS"
		  },
		  "category": "default_component_of"
		},
		{
		  "relates_to_product_reference": "openEuler-24.03-LTS",
		  "product_reference": "firefox-debugsource-115.14.0-1.oe2403.aarch64.rpm",
		  "full_product_name": {
			"product_id": "openEuler-24.03-LTS:firefox-debugsource-115.14.0-1.oe2403.aarch64",
			"name": "firefox-debugsource-115.14.0-1.oe2403.aarch64 as a component of openEuler-24.03-LTS"
		  },
		  "category": "default_component_of"
		}
	  ]
	},
	"vulnerabilities": [
	  {
		"cve": "CVE-2024-5691",
		"notes": [
		  {
			"text": "By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.",
			"category": "description",
			"title": "Vulnerability Description"
		  }
		],
		"product_status": {
		  "fixed": [
			"openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.src",
			"openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.x86_64",
			"openEuler-24.03-LTS:firefox-debuginfo-115.14.0-1.oe2403.x86_64",
			"openEuler-24.03-LTS:firefox-debugsource-115.14.0-1.oe2403.x86_64",
			"openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.aarch64",
			"openEuler-24.03-LTS:firefox-debuginfo-115.14.0-1.oe2403.aarch64",
			"openEuler-24.03-LTS:firefox-debugsource-115.14.0-1.oe2403.aarch64"
		  ]
		},
		"remediations": [
		  {
			"product_ids": [
			  "openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.src",
			  "openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.x86_64",
			  "openEuler-24.03-LTS:firefox-debuginfo-115.14.0-1.oe2403.x86_64",
			  "openEuler-24.03-LTS:firefox-debugsource-115.14.0-1.oe2403.x86_64",
			  "openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.aarch64",
			  "openEuler-24.03-LTS:firefox-debuginfo-115.14.0-1.oe2403.aarch64",
			  "openEuler-24.03-LTS:firefox-debugsource-115.14.0-1.oe2403.aarch64"
			],
			"details": "firefox security update",
			"category": "vendor_fix",
			"url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-2013"
		  }
		],
		"scores": [
		  {
			"cvss_v3": {
			  "baseSeverity": "MEDIUM",
			  "baseScore": 6.1,
			  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
			  "version": "3.1"
			},
			"products": [
			  "openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.src",
			  "openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.x86_64",
			  "openEuler-24.03-LTS:firefox-debuginfo-115.14.0-1.oe2403.x86_64",
			  "openEuler-24.03-LTS:firefox-debugsource-115.14.0-1.oe2403.x86_64",
			  "openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.aarch64",
			  "openEuler-24.03-LTS:firefox-debuginfo-115.14.0-1.oe2403.aarch64",
			  "openEuler-24.03-LTS:firefox-debugsource-115.14.0-1.oe2403.aarch64"
			]
		  }
		],
		"threats": [
		  {
			"details": "Medium",
			"category": "impact"
		  }
		],
		"title": "CVE-2024-5691"
	  }
	]
  }