ZeroHour

CVE-2018-12397

CVSS 3.0
7.1 high
EPSS
<1%p30
Published
()
Modified
Description

A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.

Vendors
mozillaredhatdebiancanonical
Products
firefox, enterprise linux desktop, enterprise linux server, enterprise linux server eus, enterprise linux workstation, debian linux, ubuntu linux
Weakness
CWE-200
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.