PT-2017-3683 · Mozilla+2 · Firefox+2

Jun Kokatsu

·

Published

2017-10-14

·

Updated

2024-12-12

·

CVE-2018-5106

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Mozilla Firefox versions prior to 58
Description: The issue is related to the implementation of the style editor component in the Developer Tools of Mozilla Firefox, which can allow traffic to be routed through a Service Worker. This can lead to the leakage of style editor information across origins if a user selects error links while the tools are open.
Recommendations: For versions prior to 58, update to version 58 or later to resolve the issue. As a temporary workaround, consider avoiding the selection of error links when the Developer Tools are open to minimize the risk of information leakage. Restrict access to the style editor component in the Developer Tools to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1178
ALT-PU-2018-1854
BDU:2018-00876
CVE-2018-5106
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
USN-3544-1
USN-3544-2

Affected Products

Alt Linux
Firefox
Ubuntu