Description
WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-10220 | WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64. |
Ubuntu USN |
USN-3844-1 | Firefox vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-05T11:08:21.948Z
Reserved: 2018-10-19T00:00:00.000Z
Link: CVE-2018-18495
No data.
Status : Modified
Published: 2019-02-28T18:29:01.680
Modified: 2024-11-21T03:56:02.767
Link: CVE-2018-18495
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN