Red Hat Bugzilla – Bug 1576280
CVE-2018-5181 Mozilla: Local file can be displayed in noopener tab through drag and drop of hyperlink
Last modified: 2018-05-24 01:18:55 EDT
If a URL using the `file:` protocol is dragged and dropped onto an open tab that is running in a different child process the tab will open a local file corresponding to the dropped URL, contrary to policy. One way to make the target tab open more reliably in a separate process is to open it with the `noopener` keyword. External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2018-11/#CVE-2018-5181
Acknowledgments: Name: the Mozilla project Upstream: Abdulrahman Alqabandi