CVE-2018-18499: Medium severity thunderbird vulnerability
A same-origin policy violation allowing the theft of cross-origin URL entries when using a <meta> meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft.
Other sources
A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2018-18499?
CVE-2018-18499 has a high severity rating due to its potential for data theft through a same-origin policy violation.
How do I fix CVE-2018-18499?
To fix CVE-2018-18499, users should update to Mozilla Firefox version 62 or later, or to the appropriate versions of Firefox ESR and Thunderbird.
Which software is affected by CVE-2018-18499?
CVE-2018-18499 affects Mozilla Firefox versions up to 62, Firefox ESR versions up to 60.2, and Thunderbird versions up to 60.2.1.
What does the CVE-2018-18499 vulnerability allow an attacker to do?
CVE-2018-18499 allows an attacker to potentially steal cross-origin URL entries and violate the same-origin policy.
When was CVE-2018-18499 disclosed?
CVE-2018-18499 was disclosed in 2018 as part of Mozilla's security advisories.