{
	"document": {
	  "aggregate_severity": {
		"namespace": "https://nvd.nist.gov/vuln-metrics/cvss",
		"text": "High"
	  },
	  "category": "csaf_vex",
	  "csaf_version": "2.0",
	  "distribution": {
		"tlp": {
		  "label": "WHITE",
		  "url": "https:/www.first.org/tlp/"
		}
	  },
	  "lang": "en",
	  "notes": [
		{
		  "text": "firefox security update",
		  "category": "general",
		  "title": "Synopsis"
		},
		{
		  "text": "An update for firefox is now available for openEuler-24.03-LTS",
		  "category": "general",
		  "title": "Summary"
		},
		{
		  "text": "Mozilla Firefox is a standalone web browser, designed for standards compliance and performance.  Its functionality can be enhanced via a plethora of extensions.\n\nSecurity Fix(es):\n\nFirefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection.  On a site protected by Content Security Policy in \"strict-dynamic\" mode, an attacker able to inject an HTML element could have used a DOM Clobbering attack on some of the shims and achieved XSS, bypassing the CSP strict-dynamic protection. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.(CVE-2024-7524)",
		  "category": "general",
		  "title": "Description"
		},
		{
		  "text": "An update for firefox is now available for openEuler-24.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.",
		  "category": "general",
		  "title": "Topic"
		},
		{
		  "text": "High",
		  "category": "general",
		  "title": "Severity"
		},
		{
		  "text": "firefox",
		  "category": "general",
		  "title": "Affected Component"
		}
	  ],
	  "publisher": {
		"issuing_authority": "openEuler security committee",
		"name": "openEuler",
		"namespace": "https://www.openeuler.org",
		"contact_details": "openeuler-security@openeuler.org",
		"category": "vendor"
	  },
	  "references": [
		{
		  "summary": "openEuler-SA-2024-2099",
		  "category": "self",
		  "url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-2099"
		},
		{
		  "summary": "CVE-2024-7524",
		  "category": "self",
		  "url": "https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-7524&packageName=firefox"
		},
		{
		  "summary": "nvd cve",
		  "category": "external",
		  "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7524"
		},
		{
		  "summary": "openEuler-SA-2024-2099 vex file",
		  "category": "self",
		  "url": "https://repo.openeuler.org/security/data/csaf/advisories/2024/csaf-openEuler-SA-2024-2099.json"
		}
	  ],
	  "title": "An update for firefox is now available for openEuler-24.03-LTS",
	  "tracking": {
		"initial_release_date": "2024-09-06T20:08:09+08:00",
		"revision_history": [
		  {
			"date": "2024-09-06T20:08:09+08:00",
			"summary": "Initial",
			"number": "1.0.0"
		  },
		  {
			"date": "2024-09-09T16:08:09+08:00",
			"summary": "final",
			"number": "2.0.0"
		  }
		],
		"generator": {
		  "date": "2024-09-09T16:08:09+08:00",
		  "engine": {
			"name": "openEuler CSAF Tool V1.0"
		  }
		},
		"current_release_date": "2024-09-09T16:08:09+08:00",
		"id": "openEuler-SA-2024-2099",
		"version": "2.0.0",
		"status": "final"
	  }
	},
	"product_tree": {
	  "branches": [
		{
		  "name": "openEuler",
		  "category": "vendor",
		  "branches": [
			{
			  "name": "openEuler",
			  "branches": [
				{
				  "product": {
					"product_identification_helper": {
					  "cpe": "cpe:/a:openEuler:openEuler:24.03-LTS"
					},
					"product_id": "openEuler-24.03-LTS",
					"name": "openEuler-24.03-LTS"
				  },
				  "name": "openEuler-24.03-LTS",
				  "category": "product_version"
				}
			  ],
			  "category": "product_name"
			},
			{
			  "name": "aarch64",
			  "branches": [
				{
				  "product": {
					"product_identification_helper": {
					  "cpe": "cpe:/a:openEuler:openEuler:24.03-LTS"
					},
					"product_id": "firefox-115.14.0-1.oe2403.aarch64.rpm",
					"name": "firefox-115.14.0-1.oe2403.aarch64.rpm"
				  },
				  "name": "firefox-115.14.0-1.oe2403.aarch64.rpm",
				  "category": "product_version"
				},
				{
				  "product": {
					"product_identification_helper": {
					  "cpe": "cpe:/a:openEuler:openEuler:24.03-LTS"
					},
					"product_id": "firefox-debuginfo-115.14.0-1.oe2403.aarch64.rpm",
					"name": "firefox-debuginfo-115.14.0-1.oe2403.aarch64.rpm"
				  },
				  "name": "firefox-debuginfo-115.14.0-1.oe2403.aarch64.rpm",
				  "category": "product_version"
				},
				{
				  "product": {
					"product_identification_helper": {
					  "cpe": "cpe:/a:openEuler:openEuler:24.03-LTS"
					},
					"product_id": "firefox-debugsource-115.14.0-1.oe2403.aarch64.rpm",
					"name": "firefox-debugsource-115.14.0-1.oe2403.aarch64.rpm"
				  },
				  "name": "firefox-debugsource-115.14.0-1.oe2403.aarch64.rpm",
				  "category": "product_version"
				}
			  ],
			  "category": "architecture"
			},
			{
			  "name": "src",
			  "branches": [
				{
				  "product": {
					"product_identification_helper": {
					  "cpe": "cpe:/a:openEuler:openEuler:24.03-LTS"
					},
					"product_id": "firefox-115.14.0-1.oe2403.src.rpm",
					"name": "firefox-115.14.0-1.oe2403.src.rpm"
				  },
				  "name": "firefox-115.14.0-1.oe2403.src.rpm",
				  "category": "product_version"
				}
			  ],
			  "category": "architecture"
			},
			{
			  "name": "x86_64",
			  "branches": [
				{
				  "product": {
					"product_identification_helper": {
					  "cpe": "cpe:/a:openEuler:openEuler:24.03-LTS"
					},
					"product_id": "firefox-115.14.0-1.oe2403.x86_64.rpm",
					"name": "firefox-115.14.0-1.oe2403.x86_64.rpm"
				  },
				  "name": "firefox-115.14.0-1.oe2403.x86_64.rpm",
				  "category": "product_version"
				},
				{
				  "product": {
					"product_identification_helper": {
					  "cpe": "cpe:/a:openEuler:openEuler:24.03-LTS"
					},
					"product_id": "firefox-debuginfo-115.14.0-1.oe2403.x86_64.rpm",
					"name": "firefox-debuginfo-115.14.0-1.oe2403.x86_64.rpm"
				  },
				  "name": "firefox-debuginfo-115.14.0-1.oe2403.x86_64.rpm",
				  "category": "product_version"
				},
				{
				  "product": {
					"product_identification_helper": {
					  "cpe": "cpe:/a:openEuler:openEuler:24.03-LTS"
					},
					"product_id": "firefox-debugsource-115.14.0-1.oe2403.x86_64.rpm",
					"name": "firefox-debugsource-115.14.0-1.oe2403.x86_64.rpm"
				  },
				  "name": "firefox-debugsource-115.14.0-1.oe2403.x86_64.rpm",
				  "category": "product_version"
				}
			  ],
			  "category": "architecture"
			}
		  ]
		}
	  ],
	  "relationships": [
		{
		  "relates_to_product_reference": "openEuler-24.03-LTS",
		  "product_reference": "firefox-115.14.0-1.oe2403.aarch64.rpm",
		  "full_product_name": {
			"product_id": "openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.aarch64",
			"name": "firefox-115.14.0-1.oe2403.aarch64 as a component of openEuler-24.03-LTS"
		  },
		  "category": "default_component_of"
		},
		{
		  "relates_to_product_reference": "openEuler-24.03-LTS",
		  "product_reference": "firefox-debuginfo-115.14.0-1.oe2403.aarch64.rpm",
		  "full_product_name": {
			"product_id": "openEuler-24.03-LTS:firefox-debuginfo-115.14.0-1.oe2403.aarch64",
			"name": "firefox-debuginfo-115.14.0-1.oe2403.aarch64 as a component of openEuler-24.03-LTS"
		  },
		  "category": "default_component_of"
		},
		{
		  "relates_to_product_reference": "openEuler-24.03-LTS",
		  "product_reference": "firefox-debugsource-115.14.0-1.oe2403.aarch64.rpm",
		  "full_product_name": {
			"product_id": "openEuler-24.03-LTS:firefox-debugsource-115.14.0-1.oe2403.aarch64",
			"name": "firefox-debugsource-115.14.0-1.oe2403.aarch64 as a component of openEuler-24.03-LTS"
		  },
		  "category": "default_component_of"
		},
		{
		  "relates_to_product_reference": "openEuler-24.03-LTS",
		  "product_reference": "firefox-115.14.0-1.oe2403.src.rpm",
		  "full_product_name": {
			"product_id": "openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.src",
			"name": "firefox-115.14.0-1.oe2403.src as a component of openEuler-24.03-LTS"
		  },
		  "category": "default_component_of"
		},
		{
		  "relates_to_product_reference": "openEuler-24.03-LTS",
		  "product_reference": "firefox-115.14.0-1.oe2403.x86_64.rpm",
		  "full_product_name": {
			"product_id": "openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.x86_64",
			"name": "firefox-115.14.0-1.oe2403.x86_64 as a component of openEuler-24.03-LTS"
		  },
		  "category": "default_component_of"
		},
		{
		  "relates_to_product_reference": "openEuler-24.03-LTS",
		  "product_reference": "firefox-debuginfo-115.14.0-1.oe2403.x86_64.rpm",
		  "full_product_name": {
			"product_id": "openEuler-24.03-LTS:firefox-debuginfo-115.14.0-1.oe2403.x86_64",
			"name": "firefox-debuginfo-115.14.0-1.oe2403.x86_64 as a component of openEuler-24.03-LTS"
		  },
		  "category": "default_component_of"
		},
		{
		  "relates_to_product_reference": "openEuler-24.03-LTS",
		  "product_reference": "firefox-debugsource-115.14.0-1.oe2403.x86_64.rpm",
		  "full_product_name": {
			"product_id": "openEuler-24.03-LTS:firefox-debugsource-115.14.0-1.oe2403.x86_64",
			"name": "firefox-debugsource-115.14.0-1.oe2403.x86_64 as a component of openEuler-24.03-LTS"
		  },
		  "category": "default_component_of"
		}
	  ]
	},
	"vulnerabilities": [
	  {
		"cve": "CVE-2024-7524",
		"notes": [
		  {
			"text": "Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection.  On a site protected by Content Security Policy in \"strict-dynamic\" mode, an attacker able to inject an HTML element could have used a DOM Clobbering attack on some of the shims and achieved XSS, bypassing the CSP strict-dynamic protection. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.",
			"category": "description",
			"title": "Vulnerability Description"
		  }
		],
		"product_status": {
		  "fixed": [
			"openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.aarch64",
			"openEuler-24.03-LTS:firefox-debuginfo-115.14.0-1.oe2403.aarch64",
			"openEuler-24.03-LTS:firefox-debugsource-115.14.0-1.oe2403.aarch64",
			"openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.src",
			"openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.x86_64",
			"openEuler-24.03-LTS:firefox-debuginfo-115.14.0-1.oe2403.x86_64",
			"openEuler-24.03-LTS:firefox-debugsource-115.14.0-1.oe2403.x86_64"
		  ]
		},
		"remediations": [
		  {
			"product_ids": [
			  "openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.aarch64",
			  "openEuler-24.03-LTS:firefox-debuginfo-115.14.0-1.oe2403.aarch64",
			  "openEuler-24.03-LTS:firefox-debugsource-115.14.0-1.oe2403.aarch64",
			  "openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.src",
			  "openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.x86_64",
			  "openEuler-24.03-LTS:firefox-debuginfo-115.14.0-1.oe2403.x86_64",
			  "openEuler-24.03-LTS:firefox-debugsource-115.14.0-1.oe2403.x86_64"
			],
			"details": "firefox security update",
			"category": "vendor_fix",
			"url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-2099"
		  }
		],
		"scores": [
		  {
			"cvss_v3": {
			  "baseSeverity": "HIGH",
			  "baseScore": 8.8,
			  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
			  "version": "3.1"
			},
			"products": [
			  "openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.aarch64",
			  "openEuler-24.03-LTS:firefox-debuginfo-115.14.0-1.oe2403.aarch64",
			  "openEuler-24.03-LTS:firefox-debugsource-115.14.0-1.oe2403.aarch64",
			  "openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.src",
			  "openEuler-24.03-LTS:firefox-115.14.0-1.oe2403.x86_64",
			  "openEuler-24.03-LTS:firefox-debuginfo-115.14.0-1.oe2403.x86_64",
			  "openEuler-24.03-LTS:firefox-debugsource-115.14.0-1.oe2403.x86_64"
			]
		  }
		],
		"threats": [
		  {
			"details": "High",
			"category": "impact"
		  }
		],
		"title": "CVE-2024-7524"
	  }
	]
  }