Red Hat Bugzilla – Bug 1265771
CVE-2015-4502 Mozilla: Scripted proxies can access inner window (MFSA 2015-108)
Last modified: 2015-09-24 12:42:03 EDT
Security researcher André Bargull reported that when a web page creates a scripted proxy for the window with a handler defined a certain way, a reference to the inner window will be passed, rather than that of the outer window in violation of the specification. External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2015-108/
Acknowledgements: Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges André Bargull as the original reporter.
This issue was fixed in Firefox version 41.