CVE-2018-5108Sensitive Information Exposure in Mozilla Firefox

Severity
4.3MEDIUMNVD
OSV9.8
EPSS
0.3%
top 46.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the private browsing tab and a normal tab. This could allow for the leaking of private information specific to the private browsing context. This issue is mitigated by the requirement that the user enter the Blob URL manually in order for the access violation to occur. This vulnerability affects Firefox < 58.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

debiandebian/firefox< firefox 58.0-1 (sid)
CVEListV5mozilla/firefoxunspecified58
Ubuntumozilla/firefox< 58.0.2+build1-0ubuntu0.14.04.1+4
NVDmozilla/firefox57.0.4

Also affects: Ubuntu Linux 14.04, 16.04, 17.10

🔴Vulnerability Details

4
GHSA
GHSA-9fmf-gjw2-hq6p: A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the priv2022-05-14
OSV
firefox regressions2018-02-12
OSV
firefox vulnerabilities2018-01-24
OSV
CVE-2018-5108: A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the priv2018-01-23

📋Vendor Advisories

3
Ubuntu
Firefox regressions2018-02-12
Ubuntu
Firefox vulnerabilities2018-01-24
Debian
CVE-2018-5108: firefox - A Blob URL can violate origin attribute segregation, allowing it to be accessed ...2018