PT-2017-3676 · Mozilla+2 · Firefox+2

Jerry Decime

·

Published

2017-10-17

·

Updated

2024-12-12

·

CVE-2018-5115

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Mozilla Firefox versions prior to 58
Description: The issue is related to an authentication error in Mozilla Firefox when handling HTTP requests. This can lead to user confusion about the origin of an authentication request, potentially causing users to send private credentials to a third-party site. The problem arises when an HTTP authentication prompt is triggered by a background network request and is displayed over the currently loaded page, making it difficult for users to identify the real domain making the request.
Recommendations: For versions prior to 58, update to version 58 or later to resolve the issue. As a temporary workaround, consider being cautious when encountering HTTP authentication prompts, especially if they appear over a foreground page, and verify the domain making the request to avoid sending credentials to unauthorized sites.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1178
ALT-PU-2018-1854
BDU:2018-00867
CVE-2018-5115
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
USN-3544-1
USN-3544-2

Affected Products

Alt Linux
Firefox
Ubuntu