CVE-2018-5136: Input Validation
Published Mar 13, 2018
·Updated
A shared worker created from a "data:" URL in one tab can be shared by another tab with a different origin, bypassing the same-origin policy. This vulnerability affects Firefox < 59.
Other sources
A shared worker created from a data: URL in one tab can be shared by another tab with a different origin, bypassing the same-origin policy.
Affected Software
6 affected componentsFixes available
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.10
Mozilla Firefox<59.0
Mozilla Firefox<59
59
debian/firefox
147.0.4-1
Event History
Mar 13, 2018
CVE Published
12:00 AM
Jun 11, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Data Sourced
via NVD·09:29 PM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:06 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·12:49 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·12:49 AM
DescriptionAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-5136.
2
What is the severity of CVE-2018-5136?
The severity of CVE-2018-5136 is high, with a severity value of 7.5.
3
Which software is affected by CVE-2018-5136?
Firefox versions prior to 59 are affected by CVE-2018-5136.
4
How can the same-origin policy be bypassed in CVE-2018-5136?
A shared worker created from a "data:" URL in one tab can be shared by another tab with a different origin, bypassing the same-origin policy.
5
How can I fix CVE-2018-5136?
To fix CVE-2018-5136, update Firefox to version 59 or later.