Red Hat Bugzilla – Bug 1642185
CVE-2018-12395 Mozilla: WebExtension bypass of domain restrictions through header rewriting
Last modified: 2018-10-24 18:10:10 EDT
By rewriting the `Host` request headers using the `webRequest` API, a WebExtension can bypass domain restrictions through domain fronting. This would allow access to domains that share a host that are otherwise restricted. External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/#CVE-2018-12395
Acknowledgments: Name: the Mozilla project Upstream: Rob Wu, Andrew Swan
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2018:3005 https://access.redhat.com/errata/RHSA-2018:3005
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2018:3006 https://access.redhat.com/errata/RHSA-2018:3006