CVE-2024-47884

Insecure Temporary File in `foxmarks`

Description

foxmarks is a CLI read-only interface for Firefox's bookmarks and history. A temporary file was created under the /tmp directory with read permissions for all users containing a copy of Firefox's database of bookmarks, history, input history, visits counter, use counter, view counter and more confidential information about the history of using Firefox. Permissions default to 0o600 for NamedTempFile. However, after copying the database, its permissions were copied with it resulting in an insecure file with 0x644 permissions. A malicious user is able to read the database when the targeted user executes foxmarks bookmarks or foxmarks history. This vulnerability is patched in v2.1.0.

Category

6.8
CVSS
Severity: Medium
CVSS 4.0 •
EPSS 0.03%
Affected: zefr0x foxmarks
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2024-47884?
CVE-2024-47884 has been scored as a medium severity vulnerability.
How to fix CVE-2024-47884?
To fix CVE-2024-47884, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2024-47884 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2024-47884 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2024-47884?
CVE-2024-47884 affects zefr0x foxmarks.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.