cbcvebase.
CVE-2018-5152
published 2018-06-11

CVE-2018-5152: WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com and listen to network traffic to the…

PriorityP431medium6.5CVSS 3.0
AVNACLPRNUIRSUCHINAN
EPSS
1.65%
73.7th percentile
WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com and listen to network traffic to the site through the "webRequest" API. For example, this allows for the interception of username and an encrypted password during login to Firefox Accounts. This issue does not expose synchronization traffic directly and is limited to the process of user login to the website and the data displayed to the user once logged in. This vulnerability affects Firefox < 60.

Affected

13 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianfirefox< firefox 60.0-1 (sid)firefox 60.0-1 (sid)
mozillafirefox< 60.060.0
mozillafirefox>= 0 < 60.0+build2-0ubuntu0.14.04.160.0+build2-0ubuntu0.14.04.1
mozillafirefox>= 0 < 60.0.1+build2-0ubuntu0.14.04.160.0.1+build2-0ubuntu0.14.04.1
mozillafirefox>= 0 < 60.0+build2-0ubuntu0.16.04.160.0+build2-0ubuntu0.16.04.1
mozillafirefox>= 0 < 60.0.1+build2-0ubuntu0.16.04.160.0.1+build2-0ubuntu0.16.04.1
mozillafirefox>= 0 < 60.0+build2-0ubuntu160.0+build2-0ubuntu1
mozillafirefox>= 0 < 60.0.1+build2-0ubuntu0.18.04.160.0.1+build2-0ubuntu0.18.04.1
mozillafirefox>= unspecified < 6060

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.