CVE-2018-5131Sensitive Information Exposure in Mozilla Firefox

Severity
5.9MEDIUMNVD
OSV8.8
EPSS
1.3%
top 20.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache header instead of downloading a copy from the network as it should. This can result in previously stored, locally cached data of a website being accessible to users if they share a common profile while browsing. This vulnerability affects Firefox ESR < 52.7 and Firefox < 59.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages7 packages

CVEListV5mozilla/firefoxunspecified59
NVDmozilla/firefox< 59.0+1
CVEListV5mozilla/firefox_esrunspecified52.7
Ubuntumozilla/firefox< 59.0+build5-0ubuntu0.14.04.1+3

Also affects: Debian Linux 7.0, 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.10, Enterprise Linux 7.4, 7.5

🔴Vulnerability Details

5
GHSA
GHSA-hf84-87fj-v8xv: Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache head2022-05-14
OSV
CVE-2018-5131: Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache head2018-06-11
CVEList
CVE-2018-5131: Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache head2018-06-11
OSV
firefox regression2018-04-06
OSV
firefox vulnerabilities2018-03-14

📋Vendor Advisories

4
Ubuntu
Firefox regression2018-04-06
Red Hat
Mozilla: Fetch API improperly returns cached copies of no-store/no-cache resources (MFSA 2018-07)2018-03-14
Ubuntu
Firefox vulnerabilities2018-03-14
Debian
CVE-2018-5131: firefox - Under certain circumstances the "fetch()" API can return transient local copies ...2018

💬Community

2
Bugzilla
Cache-Control header is ignored in Cache API2018-04-03
Bugzilla
CVE-2018-5131 Mozilla: Fetch API improperly returns cached copies of no-store/no-cache resources (MFSA 2018-07)2018-03-14
CVE-2018-5131 — Sensitive Information Exposure | cvebase