PT-2017-3683 · Mozilla+2 · Firefox+2

Jun Kokatsu

·

Publicado

2017-10-14

·

Atualizado

2024-12-12

·

CVE-2018-5106

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Mozilla Firefox versions prior to 58
Description: The issue is related to the implementation of the style editor component in the Developer Tools of Mozilla Firefox, which can allow traffic to be routed through a Service Worker. This can lead to the leakage of style editor information across origins if a user selects error links while the tools are open.
Recommendations: For versions prior to 58, update to version 58 or later to resolve the issue. As a temporary workaround, consider avoiding the selection of error links when the Developer Tools are open to minimize the risk of information leakage. Restrict access to the style editor component in the Developer Tools to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1178
ALT-PU-2018-1854
BDU:2018-00876
CVE-2018-5106
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
USN-3544-1
USN-3544-2

Produtos afetados

Alt Linux
Firefox
Ubuntu