First published: Wed Sep 05 2018(Updated: )
A same-origin policy violation allowing the theft of cross-origin URL entries when using a <meta> meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | <60.2.1 | 60.2.1 |
Firefox | <62.0 | |
Firefox ESR | <60.2 | |
Thunderbird | <60.2.1 | |
Firefox | <62 | 62 |
Firefox ESR | <60.2 | 60.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-18499 has a high severity rating due to its potential for data theft through a same-origin policy violation.
To fix CVE-2018-18499, users should update to Mozilla Firefox version 62 or later, or to the appropriate versions of Firefox ESR and Thunderbird.
CVE-2018-18499 affects Mozilla Firefox versions up to 62, Firefox ESR versions up to 60.2, and Thunderbird versions up to 60.2.1.
CVE-2018-18499 allows an attacker to potentially steal cross-origin URL entries and violate the same-origin policy.
CVE-2018-18499 was disclosed in 2018 as part of Mozilla's security advisories.