CVE-2018-12397: Infoleak
A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-12397?
CVE-2018-12397 is a vulnerability in Mozilla Firefox and Firefox ESR that allows a WebExtension to request access to local files without displaying the warning prompt to the user.
How does CVE-2018-12397 impact users?
CVE-2018-12397 allows extensions to run content scripts in local pages without permission warnings when a local file is opened, which can potentially lead to unauthorized access to user data.
Which versions of Mozilla Firefox are affected by CVE-2018-12397?
Mozilla Firefox versions up to and excluding 63.0 are affected by CVE-2018-12397.
How can I fix CVE-2018-12397?
To fix CVE-2018-12397, update your Mozilla Firefox or Firefox ESR to version 63.0 or higher.
Where can I find more information about CVE-2018-12397?
You can find more information about CVE-2018-12397 in the Mozilla Bugzilla, Mozilla Security Advisories, and MITRE CVE databases. Links: https://bugzilla.mozilla.org/show_bug.cgi?id=1487478, https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/, https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12397