CVE-2017-7843
published 2018-06-11CVE-2017-7843: When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not…
PriorityP340high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
2.99%
85.8th percentile
When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not be available in Private Browsing mode and this stored data will persist across multiple private browsing mode sessions because it is not cleared when exiting. This vulnerability affects Firefox ESR < 52.5.2 and Firefox < 57.0.1.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox | < firefox 57.0.1-1 (sid) | firefox 57.0.1-1 (sid) |
| debian | firefox-esr | < firefox 57.0.1-1 (sid) | firefox 57.0.1-1 (sid) |
| mozilla | firefox | < 57.0.1 | 57.0.1 |
| mozilla | firefox | < 52.5.2 | 52.5.2 |
| mozilla | firefox | >= unspecified < 57.0.1 | 57.0.1 |
| mozilla | firefox_esr | >= unspecified < 52.5.2 | 52.5.2 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Web worker in Private Browsing mode can write IndexedDB data
vendor_redhat·2017-12-04·CVSS 7.5
CVE-2017-7843 [HIGH] CWE-212 Mozilla: Web worker in Private Browsing mode can write IndexedDB data
Mozilla: Web worker in Private Browsing mode can write IndexedDB data
When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not be available in Private Browsing mode and this stored data will persist across multiple private browsing mode sessions because it is not cleared when exiting. This vulnerability affects Firefox ESR < 52.5.2 and Firefox < 57.0.1.
A privacy flaw was discovered in Firefox. In Private Browsing mode, a web worker could write persistent data to IndexedDB, which was not cleared when exiting and would persist across multiple sessions. A malicious website could exploit the flaw to bypass private-browsing protections and uniquely fingerprint visitors.
Debian
CVE-2017-7843: firefox - When Private Browsing mode is used, it is possible for a web worker to write per...
vendor_debian·2017·CVSS 7.5
CVE-2017-7843 [HIGH] CVE-2017-7843: firefox - When Private Browsing mode is used, it is possible for a web worker to write per...
When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not be available in Private Browsing mode and this stored data will persist across multiple private browsing mode sessions because it is not cleared when exiting. This vulnerability affects Firefox ESR < 52.5.2 and Firefox < 57.0.1.
Scope: local
sid: resolved (fixed in 57.0.1-1)
GHSA
GHSA-rpf5-xpfp-546f: When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely
ghsa_unreviewed·2022-05-14
CVE-2017-7843 [HIGH] CWE-200 GHSA-rpf5-xpfp-546f: When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely
When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not be available in Private Browsing mode and this stored data will persist across multiple private browsing mode sessions because it is not cleared when exiting. This vulnerability affects Firefox ESR < 52.5.2 and Firefox < 57.0.1.
OSV
CVE-2017-7843: When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely
osv·2018-06-11·CVSS 7.5
CVE-2017-7843 [HIGH] CVE-2017-7843: When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely
When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not be available in Private Browsing mode and this stored data will persist across multiple private browsing mode sessions because it is not cleared when exiting. This vulnerability affects Firefox ESR < 52.5.2 and Firefox < 57.0.1.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/102039http://www.securityfocus.com/bid/102112http://www.securitytracker.com/id/1039954https://access.redhat.com/errata/RHSA-2017:3382https://bugzilla.mozilla.org/show_bug.cgi?id=1410106https://lists.debian.org/debian-lts-announce/2017/12/msg00003.htmlhttps://www.debian.org/security/2017/dsa-4062https://www.mozilla.org/security/advisories/mfsa2017-27/https://www.mozilla.org/security/advisories/mfsa2017-28/http://www.securityfocus.com/bid/102039http://www.securityfocus.com/bid/102112http://www.securitytracker.com/id/1039954https://access.redhat.com/errata/RHSA-2017:3382https://bugzilla.mozilla.org/show_bug.cgi?id=1410106https://lists.debian.org/debian-lts-announce/2017/12/msg00003.htmlhttps://www.debian.org/security/2017/dsa-4062https://www.mozilla.org/security/advisories/mfsa2017-27/https://www.mozilla.org/security/advisories/mfsa2017-28/
2018-06-11
Published