CVE-2018-5114: Infoleak
If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document is closed. Network requests correctly use the changed HttpOnly cookie. This vulnerability affects Firefox < 58.
Other sources
If an existing cookie is changed to be HttpOnly while a document is open, the original value remains accessible through script until that document is closed. Network requests correctly use the changed HttpOnly cookie.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5091
- CVE-2018-5092
- CVE-2018-5093
- CVE-2018-5094
- CVE-2018-5095
- CVE-2018-5097
- CVE-2018-5098
- CVE-2018-5099
- CVE-2018-5100
- CVE-2018-5101
- CVE-2018-5102
- CVE-2018-5103
- CVE-2018-5104
- CVE-2018-5105
- CVE-2018-5106
- CVE-2018-5107
- CVE-2018-5108
- CVE-2018-5109
- CVE-2018-5110
- CVE-2018-5111
- CVE-2018-5112
- CVE-2018-5113
- CVE-2018-5114
- CVE-2018-5115
- CVE-2018-5116
- CVE-2018-5117
- CVE-2018-5118
- CVE-2018-5119
- CVE-2018-5121
- CVE-2018-5122
- CVE-2018-5090
- CVE-2018-5089
Frequently Asked Questions
What is CVE-2018-5114?
CVE-2018-5114 is a vulnerability that allows the original value of a cookie to remain accessible through script even after it has been changed to be HttpOnly.
Which versions of Firefox are affected by CVE-2018-5114?
Firefox versions before 58 are affected by CVE-2018-5114.
What is the severity of CVE-2018-5114?
CVE-2018-5114 has a severity level of 5.3, which is considered medium.
How can I fix CVE-2018-5114?
To fix CVE-2018-5114, update Firefox to version 58 or higher.
Where can I find more information about CVE-2018-5114?
You can find more information about CVE-2018-5114 on the Mozilla website and Bugzilla.