CVE-2017-7842: Infoleak
If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" elements instead of one. One of these requests includes the referrer instead of respecting the set policy to not include a referrer on requests. This vulnerability affects Firefox < 57.
Other sources
If a document’s Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for <link> elements instead of one. One of these requests includes the referrer instead of respecting the set policy to not include a referrer on requests.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2017-7842?
CVE-2017-7842 is a vulnerability that affects Firefox versions up to 57.0.2 and allows two network requests to be made for <link> elements when the Referrer Policy attribute is set to 'no-referrer', with one of these requests including the referrer against the set policy.
Which software is affected by CVE-2017-7842?
Mozilla Firefox versions up to 57.0.2 are affected by CVE-2017-7842.
What is the severity of CVE-2017-7842?
CVE-2017-7842 has a severity rating of 5.3 (medium).
What is the solution for CVE-2017-7842?
To mitigate CVE-2017-7842, users should update to Firefox version 57.0.3 or later.
Where can I find more information about CVE-2017-7842?
You can find more information about CVE-2017-7842 on Bugzilla, Mozilla's security advisories page, and SecurityFocus.