CVE-2018-12397
Summary
| CVE | CVE-2018-12397 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-02-28 18:29:00 UTC |
| Updated | 2019-03-01 15:00:00 UTC |
| Description | A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| USN-3801-1: Firefox vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Security vulnerabilities fixed in Firefox ESR 60.3 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Mozilla Firefox: Multiple vulnerabilities (GLSA 201811-04) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Mozilla Firefox and Firefox ESR Multiple Security Vulnerabilities |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Mozilla Firefox Multiple Bugs Let Remote Users Deny Service, Obtain Potentially Sensitive Information, and Execute Arbitrary Code - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Security vulnerabilities fixed in Firefox 63 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Debian -- Security Information -- DSA-4324-1 firefox-esr |
DEBIAN |
www.debian.org |
Third Party Advisory |
| 1487478 - (CVE-2018-12397) "file:///*" extension permission has no warning |
CONFIRM |
bugzilla.mozilla.org |
Issue Tracking, Permissions Required, Vendor Advisory |
| [SECURITY] [DLA 1571-1] firefox-esr security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710205 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 201811-04)