CVE-2016-2817Firefox vulnerability

CWE-26411 documents7 sources
Severity
5.4MEDIUMNVD
OSV8.8
EPSS
0.4%
top 39.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 30
Latest updateMay 17

Description

The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inheritance during chrome.tabs.create and chrome.tabs.update API calls, which allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted extension that accesses a (1) javascript: or (2) data: URL.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages4 packages

Ubuntumozilla/firefox< 46.0+build5-0ubuntu0.14.04.2+3
NVDmozilla/firefox45.0.2
debiandebian/firefox< firefox 46.0-1 (sid)
debiandebian/firefox-esr< firefox 46.0-1 (sid)

🔴Vulnerability Details

4
GHSA
GHSA-px89-65ch-24x4: The WebExtension sandbox feature in browser/components/extensions/ext-tabs2022-05-17
OSV
firefox regression2016-05-19
OSV
CVE-2016-2817: The WebExtension sandbox feature in browser/components/extensions/ext-tabs2016-04-27
OSV
firefox vulnerabilities2016-04-27

📋Vendor Advisories

5
Ubuntu
Firefox regression2016-05-19
Ubuntu
Oxygen-GTK3 update2016-05-02
Ubuntu
Firefox vulnerabilities2016-04-27
Red Hat
Mozilla: Elevation of privilege with chrome.tabs.update API in web extensions (MFSA 2016-46)2016-04-26
Debian
CVE-2016-2817: firefox - The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in...2016

💬Community

1
Bugzilla
CVE-2016-2817 Mozilla: Elevation of privilege with chrome.tabs.update API in web extensions (MFSA 2016-46)2016-04-25