PT-2017-3683 · Mozilla+2 · Firefox+2
Jun Kokatsu
·
Publicado
2017-10-14
·
Atualizado
2024-12-12
·
CVE-2018-5106
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Mozilla Firefox versions prior to 58
Description:
The issue is related to the implementation of the style editor component in the Developer Tools of Mozilla Firefox, which can allow traffic to be routed through a Service Worker. This can lead to the leakage of style editor information across origins if a user selects error links while the tools are open.
Recommendations:
For versions prior to 58, update to version 58 or later to resolve the issue. As a temporary workaround, consider avoiding the selection of error links when the Developer Tools are open to minimize the risk of information leakage. Restrict access to the style editor component in the Developer Tools to minimize the risk of exploitation.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Firefox
Ubuntu