CVE-2018-5132 — Sensitive Information Exposure in Mozilla Firefox
Severity
6.5MEDIUMNVD
OSV8.8
EPSS
0.9%
top 24.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11
Latest updateMay 14
Description
The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a malicious WebExtension to search for otherwise protected data if a user has it open. This vulnerability affects Firefox < 59.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages4 packages
Also affects: Ubuntu Linux 14.04, 16.04, 17.10
🔴Vulnerability Details
4GHSA▶
GHSA-j69q-r9wj-j9g6: The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab↗2022-05-14
OSV▶
CVE-2018-5132: The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab↗2018-03-14