Red Hat Bugzilla – Bug 1291588
CVE-2015-7215 Mozilla: Cross-origin information leak through web workers error events (MFSA 2015-140)
Last modified: 2015-12-16 04:03:57 EST
Security researcher Masato Kinugawa reported a cross-origin information leak through the error events in web workers. This violates same-origin policy and the leaked information could potentially be used by a malicious party to gather authentication tokens and other data from third-party websites. This issue affects other browsers as well and is not limited to Mozilla products. External Reference: https://www.mozilla.org/security/announce/2015/mfsa2015-140.html Acknowledgements: Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Masato Kinugawa as the original reporter. Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.