CVE-2017-7816: Input Validation
Last updated 24 July 2024
Other sources
WebExtensions could use popups and panels in the extension UI to load an "about:" privileged URL, violating security checks that disallow this behavior. This vulnerability affects Firefox < 56.
— Launchpad
WebExtensions could use popups and panels in the extension UI to load an about: privileged URL, violating security checks that disallow this behavior.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2017-7816?
CVE-2017-7816 is a vulnerability in Firefox < 56 where WebExtensions could use popups and panels in the extension UI to load an "about:" privileged URL, violating security checks.
How does CVE-2017-7816 affect Firefox?
CVE-2017-7816 affects Firefox versions earlier than 56.
What is the severity of CVE-2017-7816?
The severity of CVE-2017-7816 is medium with a CVSS score of 5.3.
How can I fix CVE-2017-7816 in Firefox?
To fix CVE-2017-7816, users should update Firefox to version 56 or later.
Where can I find more information about CVE-2017-7816?
More information about CVE-2017-7816 can be found on the Mozilla Bugzilla, Mozilla Security Advisories, and SecurityFocus websites.