First published: Tue Jan 23 2018(Updated: )
If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed over the currently loaded foreground page. Although the prompt contains the real domain making the request, this can result in user confusion about the originating site of the authentication request and may cause users to mistakenly send private credential information to a third party site.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <58 | 58 |
Mozilla Firefox | <=57.0.4 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =17.10 | |
debian/firefox | 131.0.2-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-5115 is a vulnerability where an HTTP authentication prompt triggered by a background network request is displayed over the currently loaded foreground page, causing user confusion.
Mozilla Firefox versions up to 58.0 are affected by CVE-2018-5115.
To fix CVE-2018-5115 on Ubuntu, update Firefox to version 58.0 or higher.
CVE-2018-5115 has a severity rating of 7.5 (High).
The Common Weakness Enumeration (CWE) ID of CVE-2018-5115 is 200.