CVE-2018-5131
published 2018-06-11CVE-2018-5131: Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache header…
medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache header instead of downloading a copy from the network as it should. This can result in previously stored, locally cached data of a website being accessible to users if they share a common profile while browsing. This vulnerability affects Firefox ESR < 52.7 and Firefox < 59.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox | < firefox 59.0-1 (sid) | firefox 59.0-1 (sid) |
| debian | firefox-esr | < firefox 59.0-1 (sid) | firefox 59.0-1 (sid) |
| mozilla | firefox | < 59.0 | 59.0 |
| mozilla | firefox | < 52.7.0 | 52.7.0 |
| mozilla | firefox | >= 0 < 59.0+build5-0ubuntu0.14.04.1 | 59.0+build5-0ubuntu0.14.04.1 |
| mozilla | firefox | >= 0 < 59.0.2+build1-0ubuntu0.14.04.4 | 59.0.2+build1-0ubuntu0.14.04.4 |
| mozilla | firefox | >= 0 < 59.0+build5-0ubuntu0.16.04.1 | 59.0+build5-0ubuntu0.16.04.1 |
| mozilla | firefox | >= 0 < 59.0.2+build1-0ubuntu0.16.04.3 | 59.0.2+build1-0ubuntu0.16.04.3 |
| mozilla | firefox | >= unspecified < 59 | 59 |
| mozilla | firefox_esr | >= unspecified < 52.7 | 52.7 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv8.8HIGH