First published: Tue Oct 23 2018(Updated: )
A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the WebExtension on sites where content scripts should not be run.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <60.3 | 60.3 |
Mozilla Firefox | <63 | 63 |
Mozilla Firefox | <63.0 | |
Mozilla Firefox ESR | <60.3 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =18.10 | |
Redhat Enterprise Linux Desktop | =6.0 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Server | =6.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Server Aus | =7.6 | |
Redhat Enterprise Linux Server Eus | =7.6 | |
Redhat Enterprise Linux Server Tus | =7.6 | |
Redhat Enterprise Linux Workstation | =6.0 | |
Redhat Enterprise Linux Workstation | =7.0 | |
debian/firefox | 133.0.3-1 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.5.0esr-1~deb11u1 128.3.1esr-1~deb12u1 128.5.0esr-1~deb12u1 128.5.0esr-1 128.5.1esr-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-12396 is a vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events, potentially allowing for privilege escalation.
Firefox ESR < 60.3 and Firefox < 63.0 are affected by CVE-2018-12396.
CVE-2018-12396 has a severity rating of 6.5, which is considered medium.
To fix CVE-2018-12396, update Firefox ESR to version 60.3 or later, or update Firefox to version 63.0 or later.
You can find more information about CVE-2018-12396 on the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1483602), [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/), [CVE Mitre](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12396).