PT-2017-3683 · Mozilla+2 · Firefox+2
Jun Kokatsu
·
Published
2017-10-14
·
Updated
2024-12-12
·
CVE-2018-5106
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Mozilla Firefox versions prior to 58
Description:
The issue is related to the implementation of the style editor component in the Developer Tools of Mozilla Firefox, which can allow traffic to be routed through a Service Worker. This can lead to the leakage of style editor information across origins if a user selects error links while the tools are open.
Recommendations:
For versions prior to 58, update to version 58 or later to resolve the issue. As a temporary workaround, consider avoiding the selection of error links when the Developer Tools are open to minimize the risk of information leakage. Restrict access to the style editor component in the Developer Tools to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Firefox
Ubuntu