Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-18499

Опубликовано: 05 сент. 2018
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5firefoxOut of support scope
Red Hat Enterprise Linux 5thunderbirdOut of support scope
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 8thunderbirdNot affected
Red Hat Enterprise Linux 6firefoxFixedRHSA-2018:269312.09.2018
Red Hat Enterprise Linux 6thunderbirdFixedRHSA-2018:340330.10.2018
Red Hat Enterprise Linux 7firefoxFixedRHSA-2018:269212.09.2018
Red Hat Enterprise Linux 7thunderbirdFixedRHSA-2018:345805.11.2018

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-829
https://bugzilla.redhat.com/show_bug.cgi?id=1849971Mozilla: Same-origin policy violation using meta refresh and performance.getEntries to steal cross-origin URLs

EPSS

Процентиль: 42%
0.00198
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 7 лет назад

A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

CVSS3: 6.5
nvd
почти 7 лет назад

A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

CVSS3: 6.5
debian
почти 7 лет назад

A same-origin policy violation allowing the theft of cross-origin URL ...

CVSS3: 6.5
github
больше 3 лет назад

A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

EPSS

Процентиль: 42%
0.00198
Низкий

6.5 Medium

CVSS3