A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the private browsing tab and a normal tab. This could allow for the leaking of private information specific to the private browsing context. This issue is mitigated by the requirement that the user enter the Blob URL manually in order for the access violation to occur. This vulnerability affects Firefox < 58.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/102786 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1040270 | VDB Entry Third Party Advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=1421099 | Issue Tracking Permissions Required |
https://usn.ubuntu.com/3544-1/ | Third Party Advisory |
https://www.mozilla.org/security/advisories/mfsa2018-02/ | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2018-06-11 21:29
Updated : 2024-02-04 19:46
NVD link : CVE-2018-5108
Mitre link : CVE-2018-5108
CVE.ORG link : CVE-2018-5108
JSON object : View
Products Affected
mozilla
- firefox
canonical
- ubuntu_linux
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor