Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-5113

Опубликовано: 11 июн. 2018
Источник: debian

Описание

The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but this requirement was not properly enforced. This can potentially allow privileged pages to be loaded by the extension. This vulnerability affects Firefox < 58.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed58.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-02/#CVE-2018-5113

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but this requirement was not properly enforced. This can potentially allow privileged pages to be loaded by the extension. This vulnerability affects Firefox < 58.

CVSS3: 7.5
nvd
больше 7 лет назад

The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but this requirement was not properly enforced. This can potentially allow privileged pages to be loaded by the extension. This vulnerability affects Firefox < 58.

CVSS3: 7.5
github
больше 3 лет назад

The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but this requirement was not properly enforced. This can potentially allow privileged pages to be loaded by the extension. This vulnerability affects Firefox < 58.

CVSS3: 7.5
fstec
около 8 лет назад

Уязвимость функции browser.identity.launchWebAuthFlow расширения WebExtensions браузера Mozilla Firefox, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации