CVE-2018-5106: Infoleak
Last updated 24 July 2024
Other sources
Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a user selects error links when these tools are open. This can allow style editor information used within Developer Tools to leak cross-origin.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5091
- CVE-2018-5092
- CVE-2018-5093
- CVE-2018-5094
- CVE-2018-5095
- CVE-2018-5097
- CVE-2018-5098
- CVE-2018-5099
- CVE-2018-5100
- CVE-2018-5101
- CVE-2018-5102
- CVE-2018-5103
- CVE-2018-5104
- CVE-2018-5105
- CVE-2018-5106
- CVE-2018-5107
- CVE-2018-5108
- CVE-2018-5109
- CVE-2018-5110
- CVE-2018-5111
- CVE-2018-5112
- CVE-2018-5113
- CVE-2018-5114
- CVE-2018-5115
- CVE-2018-5116
- CVE-2018-5117
- CVE-2018-5118
- CVE-2018-5119
- CVE-2018-5121
- CVE-2018-5122
- CVE-2018-5090
- CVE-2018-5089
Frequently Asked Questions
What is CVE-2018-5106?
CVE-2018-5106 is a vulnerability that allows style editor traffic in the Developer Tools to be routed through a service worker hosted on a third-party website, potentially leaking cross-origin information.
Which software is affected by CVE-2018-5106?
This vulnerability affects Firefox versions up to but excluding 58.0, as well as certain versions of the Firefox package in Ubuntu and Canonical Ubuntu Linux.
What is the severity of CVE-2018-5106?
CVE-2018-5106 has a severity level of medium, with a severity value of 5.3.
How can I fix CVE-2018-5106?
To fix CVE-2018-5106, you should update your Firefox browser to version 58.0 or later. Additionally, ensure that your Ubuntu or Canonical Ubuntu Linux system is updated to include the recommended versions of the Firefox package.
Where can I find more information about CVE-2018-5106?
You can find more information about CVE-2018-5106 in the following references: [https://bugzilla.mozilla.org/show_bug.cgi?id=1408708](https://bugzilla.mozilla.org/show_bug.cgi?id=1408708), [https://www.mozilla.org/en-US/security/advisories/mfsa2018-02/](https://www.mozilla.org/en-US/security/advisories/mfsa2018-02/), [https://www.mozilla.org/security/advisories/mfsa2018-02/](https://www.mozilla.org/security/advisories/mfsa2018-02/)