CVE-2018-12398: Medium severity Mozilla Firefox vulnerability
Published Oct 23, 2018
·Updated
By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (CSP).
Affected Software
7 affected componentsFixes available
Mozilla Firefox<63.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Mozilla Firefox<63
63
debian/firefox
149.0.2-1
Event History
Oct 23, 2018
CVE Published
12:00 AM
Feb 28, 2019
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Jan 11, 2024
Data Sourced
via Launchpad·10:49 PM
Description
Nov 30, 2025
Data Sourced
via Ubuntu·06:17 PM
RemedyDescriptionSeverityAffected Software
Apr 10, 2026
Data Sourced
via Debian·05:02 PM
DescriptionAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-12398.
2
Which software versions are affected by this vulnerability?
This vulnerability affects Firefox versions < 63.
3
How does this vulnerability work?
By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (CSP).
4
What is the severity of CVE-2018-12398?
CVE-2018-12398 has a severity rating of medium.
5
How can I fix the vulnerability in Firefox?
To fix the vulnerability, update Firefox to version 63 or higher.