A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the private browsing tab and a normal tab. This could allow for the leaking of private information specific to the private browsing context. This issue is mitigated by the requirement that the user enter the Blob URL manually in order for the access violation to occur. This vulnerability affects Firefox < 58.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/102786 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1040270 | Third Party Advisory VDB Entry |
https://bugzilla.mozilla.org/show_bug.cgi?id=1421099 | Issue Tracking Permissions Required |
https://usn.ubuntu.com/3544-1/ | Third Party Advisory |
https://www.mozilla.org/security/advisories/mfsa2018-02/ | Vendor Advisory |
http://www.securityfocus.com/bid/102786 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1040270 | Third Party Advisory VDB Entry |
https://bugzilla.mozilla.org/show_bug.cgi?id=1421099 | Issue Tracking Permissions Required |
https://usn.ubuntu.com/3544-1/ | Third Party Advisory |
https://www.mozilla.org/security/advisories/mfsa2018-02/ | Vendor Advisory |
Configurations
History
21 Nov 2024, 04:08
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/102786 - Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id/1040270 - Third Party Advisory, VDB Entry | |
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=1421099 - Issue Tracking, Permissions Required | |
References | () https://usn.ubuntu.com/3544-1/ - Third Party Advisory | |
References | () https://www.mozilla.org/security/advisories/mfsa2018-02/ - Vendor Advisory |
Information
Published : 2018-06-11 21:29
Updated : 2024-11-21 04:08
NVD link : CVE-2018-5108
Mitre link : CVE-2018-5108
CVE.ORG link : CVE-2018-5108
JSON object : View
Products Affected
canonical
- ubuntu_linux
mozilla
- firefox
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor