First published: Tue Jun 26 2018(Updated: )
Last updated 24 July 2024
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/firefox | 135.0.1-1 | |
Firefox | <61.0 | |
Firefox ESR | <60.1.0 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =17.10 | |
Ubuntu | =18.04 | |
Firefox | <61 | 61 |
Firefox ESR | <60.1 | 60.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-12369 is considered a high severity vulnerability due to its potential to allow full browser permissions to malicious WebExtensions.
To fix CVE-2018-12369, update your Mozilla Firefox to a version greater than 61 or Mozilla Firefox ESR to a version greater than 60.1.
CVE-2018-12369 affects Mozilla Firefox ESR versions up to 60.1 and Mozilla Firefox versions up to 61.
CVE-2018-12369 is an authorization bypass vulnerability related to the handling of bundled WebExtensions.
Yes, CVE-2018-12369 can be exploited remotely by using malicious WebExtensions to gain unauthorized access to browser permissions.