cbcvebase.
CVE-2018-12397
published 2019-02-28

CVE-2018-12397: A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed…

high7.1CVSS 3.0
AVLACLPRLUINSUCHIHAN
A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.

Affected

25 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianfirefox< firefox 63.0-1 (sid)firefox 63.0-1 (sid)
debianfirefox-esr< firefox 63.0-1 (sid)firefox 63.0-1 (sid)
mozillafirefox< 60.3.060.3.0
mozillafirefox< 63.063.0
mozillafirefox>= 0 < 63.0.3+build1-0ubuntu0.14.04.163.0.3+build1-0ubuntu0.14.04.1
mozillafirefox>= 0 < 63.0+build2-0ubuntu0.14.04.263.0+build2-0ubuntu0.14.04.2
mozillafirefox>= 0 < 63.0.3+build1-0ubuntu0.16.04.163.0.3+build1-0ubuntu0.16.04.1
mozillafirefox>= 0 < 63.0+build2-0ubuntu0.16.04.263.0+build2-0ubuntu0.16.04.2
mozillafirefox>= 0 < 63.0.3+build1-0ubuntu0.18.04.163.0.3+build1-0ubuntu0.18.04.1
mozillafirefox>= 0 < 63.0+build2-0ubuntu0.18.04.263.0+build2-0ubuntu0.18.04.2
mozillafirefox>= unspecified < 6363
mozillafirefox_esr>= unspecified < 60.360.3
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_eus
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation

CVSS provenance

nvdv3.07.1HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
osv8.8HIGH