First published: Tue Nov 14 2017(Updated: )
If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" elements instead of one. One of these requests includes the referrer instead of respecting the set policy to not include a referrer on requests. This vulnerability affects Firefox < 57.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <57 | 57 |
Mozilla Firefox | <=56.0.2 | |
debian/firefox | 131.0.2-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-7842 is a vulnerability that affects Firefox versions up to 57.0.2 and allows two network requests to be made for <link> elements when the Referrer Policy attribute is set to 'no-referrer', with one of these requests including the referrer against the set policy.
Mozilla Firefox versions up to 57.0.2 are affected by CVE-2017-7842.
CVE-2017-7842 has a severity rating of 5.3 (medium).
To mitigate CVE-2017-7842, users should update to Firefox version 57.0.3 or later.
You can find more information about CVE-2017-7842 on Bugzilla, Mozilla's security advisories page, and SecurityFocus.