CVE-2018-5164 — Cross-site Scripting in Mozilla Firefox
Severity
6.1MEDIUMNVD
OSV9.8
EPSS
0.4%
top 40.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11
Latest updateMay 14
Description
Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixed-replace" MIME type. This could allow for script to run where CSP should block it, allowing for cross-site scripting (XSS) and other attacks. This vulnerability affects Firefox < 60.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7
Affected Packages4 packages
Also affects: Ubuntu Linux 14.04, 16.04, 17.10, 18.04
🔴Vulnerability Details
4GHSA▶
GHSA-qqvm-q62q-qw92: Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixed-replace" MIME type↗2022-05-14
OSV▶
CVE-2018-5164: Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixed-replace" MIME type↗2018-05-11
📋Vendor Advisories
4Red Hat
▶
Debian▶
CVE-2018-5164: firefox - Content Security Policy (CSP) is not applied correctly to all parts of multipart...↗2018
💬Community
1Bugzilla▶
CVE-2018-5164 Mozilla: CSP not applied to all multipart content sent with multipart/x-mixed-replace↗2018-05-09