CVE-2018-12391Incorrect Authorization in Mozilla Firefox

Severity
8.8HIGHNVD
EPSS
0.5%
top 32.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 28
Latest updateMay 13

Description

During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the problem is in the underlying Android service, this issue is addressed by treating all HLS streams as cross-origin and opaque to access. *Note: this issue only affects Firefox for Android. Desktop versions of Firefox are unaffected.*. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified63
NVDmozilla/firefox< 63.0
CVEListV5mozilla/firefox_esrunspecified60.3

🔴Vulnerability Details

1
GHSA
GHSA-77j4-f249-58h4: During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies2022-05-13

📋Vendor Advisories

2
Red Hat
Mozilla: HTTP Live Stream audio data is accessible cross-origin2018-10-23
Debian
CVE-2018-12391: firefox - During HTTP Live Stream playback on Firefox for Android, audio data can be acces...2018

💬Community

1
Bugzilla
CVE-2018-12391 Mozilla: HTTP Live Stream audio data is accessible cross-origin2018-10-23