Bug 1696138 (CVE-2018-18495) - CVE-2018-18495 firefox: WebExtension content scripts can be loaded in about: pages
Summary: CVE-2018-18495 firefox: WebExtension content scripts can be loaded in about: ...
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2018-18495
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1692767
TreeView+ depends on / blocked
 
Reported: 2019-04-04 08:29 UTC by msiddiqu
Modified: 2019-09-29 15:10 UTC (History)
11 users (show)

Fixed In Version: firefox 64
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-04-05 03:13:38 UTC


Attachments (Terms of Use)

Description msiddiqu 2019-04-04 08:29:59 UTC
WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.

References:
https://bugzilla.mozilla.org/show_bug.cgi?id=1427585

External References: 
https://www.mozilla.org/en-US/security/advisories/mfsa2018-29/#CVE-2018-18495


Note You need to log in before you can comment on or make changes to this bug.