← Back to CVE List

CVE-2024-1554

Published: 2024-02-20T14:15Z
Last Modified: 2025-04-02T20:12Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Under the correct circumstances, an attacker may have been able to poison the local browser cache by priming it with a `fetch()` response controlled by the additional headers. Upon navigation to the same URL, the user would see the cached response instead of the expected response. This vulnerability affects Firefox < 123. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt