Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-18495

Опубликовано: 11 дек. 2018
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6firefoxWill not fix
Red Hat Enterprise Linux 7firefoxWill not fix
Red Hat Enterprise Linux 8firefoxWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20->CWE-59
Дефект:
CWE-270
Дефект:
CWE-552->CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1696138firefox: WebExtension content scripts can be loaded in about: pages

EPSS

Процентиль: 55%
0.00328
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 7 лет назад

WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.

CVSS3: 6.5
nvd
почти 7 лет назад

WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.

CVSS3: 6.5
debian
почти 7 лет назад

WebExtension content scripts can be loaded into about: pages in some c ...

CVSS3: 6.5
github
больше 3 лет назад

WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.

CVSS3: 6.5
fstec
почти 7 лет назад

Уязвимость компонента WebExtension браузера Firefox, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 55%
0.00328
Низкий

6.5 Medium

CVSS3