CVE-2018-5137: Infoleak
A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. This script does this by using a maliciously crafted path string to reference the resources. Note: this vulnerability does not affect WebExtensions.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-5137?
CVE-2018-5137 is a vulnerability in Firefox where a legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script.
How does CVE-2018-5137 affect Firefox?
CVE-2018-5137 affects Firefox versions up to but excluding 59.0.
What is the severity of CVE-2018-5137?
CVE-2018-5137 has a severity rating of 7.5 (High).
How can I fix CVE-2018-5137 in Firefox?
To fix CVE-2018-5137, update Firefox to version 59.0 or higher.
Where can I find more information about CVE-2018-5137?
More information about CVE-2018-5137 can be found at the following references: [link1], [link2], [link3].