First published: Tue Oct 23 2018(Updated: )
A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the WebExtension on sites where content scripts should not be run.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <63 | 63 |
Firefox ESR | <60.3 | 60.3 |
Firefox | <63.0 | |
Firefox ESR | <60.3 | |
Debian Linux | =8.0 | |
Debian Linux | =9.0 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =18.10 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Red Hat Enterprise Linux Workstation | =7.0 | |
debian/firefox | 137.0-1 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.9.0esr-1~deb11u1 128.8.0esr-1~deb12u1 128.9.0esr-1~deb12u1 128.8.0esr-1 128.9.0esr-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-12396 is a vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events, potentially allowing for privilege escalation.
Firefox ESR < 60.3 and Firefox < 63.0 are affected by CVE-2018-12396.
CVE-2018-12396 has a severity rating of 6.5, which is considered medium.
To fix CVE-2018-12396, update Firefox ESR to version 60.3 or later, or update Firefox to version 63.0 or later.
You can find more information about CVE-2018-12396 on the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1483602), [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/), [CVE Mitre](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12396).