CVE-2018-18494: Medium severity Mozilla Thunderbird vulnerability
A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-30/#CVE-2018-18494
Other sources
A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-18494?
CVE-2018-18494 is a vulnerability that allows the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries().
Which software is affected by CVE-2018-18494?
Mozilla Firefox (up to version 64), Mozilla Firefox ESR (up to version 60.4), and Mozilla Thunderbird (up to version 60.4) are affected by CVE-2018-18494.
What is the severity of CVE-2018-18494?
CVE-2018-18494 has a severity rating of 6.5 (High).
How can I fix CVE-2018-18494?
Update Mozilla Firefox to version 64 or later, Mozilla Firefox ESR to version 60.4.1 or later, and Mozilla Thunderbird to version 60.4.1 or later to fix CVE-2018-18494.
Where can I find more information about CVE-2018-18494?
You can find more information about CVE-2018-18494 on the Mozilla Bugzilla and Mozilla security advisories websites.