If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed over the currently loaded foreground page. Although the prompt contains the real domain making the request, this can result in user confusion about the originating site of the authentication request and may cause users to mistakenly send private credential information to a third party site. This vulnerability affects Firefox < 58.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mozilla
Published: 2018-06-11T21:00:00
Updated: 2024-08-05T05:26:46.685Z
Reserved: 2018-01-03T00:00:00
Link: CVE-2018-5115
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-06-11T21:29:13.483
Modified: 2024-11-21T04:08:08.380
Link: CVE-2018-5115
Redhat
No data.