CVE-2018-5108 — Sensitive Information Exposure in Mozilla Firefox
Severity
4.3MEDIUMNVD
OSV9.8
EPSS
0.3%
top 46.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11
Latest updateMay 14
Description
A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the private browsing tab and a normal tab. This could allow for the leaking of private information specific to the private browsing context. This issue is mitigated by the requirement that the user enter the Blob URL manually in order for the access violation to occur. This vulnerability affects Firefox < 58.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4
Affected Packages4 packages
Also affects: Ubuntu Linux 14.04, 16.04, 17.10
🔴Vulnerability Details
4GHSA▶
GHSA-9fmf-gjw2-hq6p: A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the priv↗2022-05-14
OSV▶
CVE-2018-5108: A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the priv↗2018-01-23