CVE-2018-5157: Infoleak
Last updated 24 July 2024
Other sources
Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5154
- CVE-2018-5155
- CVE-2018-5157
- CVE-2018-5158
- CVE-2018-5159
- CVE-2018-5160
- CVE-2018-5152
- CVE-2018-5153
- CVE-2018-5163
- CVE-2018-5164
- CVE-2018-5166
- CVE-2018-5167
- CVE-2018-5168
- CVE-2018-5169
- CVE-2018-5172
- CVE-2018-5173
- CVE-2018-5174
- CVE-2018-5175
- CVE-2018-5176
- CVE-2018-5177
- CVE-2018-5165
- CVE-2018-5180
- CVE-2018-5181
- CVE-2018-5182
- CVE-2018-5179
- CVE-2018-5151
- CVE-2018-5150
- CVE-2018-5183
- CVE-2018-5178
Frequently Asked Questions
What is CVE-2018-5157?
CVE-2018-5157 is a vulnerability that allows a malicious site to bypass same-origin protections for the PDF viewer and intercept messages meant for the viewer, potentially accessing restricted PDF files.
Which software versions are affected by CVE-2018-5157?
Firefox ESR versions earlier than 52.8 and Firefox versions earlier than 60.0 are affected by CVE-2018-5157.
What is the severity of CVE-2018-5157?
CVE-2018-5157 has a severity score of 7, which is considered high.
How can I fix CVE-2018-5157?
To fix CVE-2018-5157, update your Firefox ESR version to 52.8 or later, and update your Firefox version to 60.0 or later.
Where can I find more information about CVE-2018-5157?
You can find more information about CVE-2018-5157 on the Mozilla Bugzilla website, Mozilla Security Advisories website, and SecurityFocus website.