CVE-2018-5164: XSS
Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixed-replace" MIME type. This could allow for script to run where CSP should block it, allowing for cross-site scripting (XSS) and other attacks. This vulnerability affects Firefox < 60.
Other sources
Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the multipart/x-mixed-replace MIME type. This could allow for script to run where CSP should block it, allowing for cross-site scripting (XSS) and other attacks.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5154
- CVE-2018-5155
- CVE-2018-5157
- CVE-2018-5158
- CVE-2018-5159
- CVE-2018-5160
- CVE-2018-5152
- CVE-2018-5153
- CVE-2018-5163
- CVE-2018-5164
- CVE-2018-5166
- CVE-2018-5167
- CVE-2018-5168
- CVE-2018-5169
- CVE-2018-5172
- CVE-2018-5173
- CVE-2018-5174
- CVE-2018-5175
- CVE-2018-5176
- CVE-2018-5177
- CVE-2018-5165
- CVE-2018-5180
- CVE-2018-5181
- CVE-2018-5182
- CVE-2018-5179
- CVE-2018-5151
- CVE-2018-5150
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-5164.
What is the severity rating of CVE-2018-5164?
CVE-2018-5164 has a severity rating of 6.1, which is considered medium.
Which software is affected by CVE-2018-5164?
Mozilla Firefox versions up to, but excluding, 60.0 are affected by CVE-2018-5164.
What is the impact of CVE-2018-5164?
CVE-2018-5164 could allow for cross-site scripting (XSS) and other attacks by not correctly applying Content Security Policy (CSP) to all parts of multipart content.
Are there any remediation steps for CVE-2018-5164?
Yes, upgrading Mozilla Firefox to version 60.0 or higher will address the vulnerability.