CVE-2018-5166: High severity ubuntu vulnerability
Last updated 24 July 2024
Other sources
WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission. This vulnerability affects Firefox < 60.
— Launchpad
WebExtensions can use request redirection and a filterReponseData filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5154
- CVE-2018-5155
- CVE-2018-5157
- CVE-2018-5158
- CVE-2018-5159
- CVE-2018-5160
- CVE-2018-5152
- CVE-2018-5153
- CVE-2018-5163
- CVE-2018-5164
- CVE-2018-5166
- CVE-2018-5167
- CVE-2018-5168
- CVE-2018-5169
- CVE-2018-5172
- CVE-2018-5173
- CVE-2018-5174
- CVE-2018-5175
- CVE-2018-5176
- CVE-2018-5177
- CVE-2018-5165
- CVE-2018-5180
- CVE-2018-5181
- CVE-2018-5182
- CVE-2018-5179
- CVE-2018-5151
- CVE-2018-5150
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-5166.
What software is affected by CVE-2018-5166?
Firefox versions prior to 60 are affected by CVE-2018-5166.
How can WebExtensions bypass host permission settings using CVE-2018-5166?
WebExtensions can use request redirection and a "filterReponseData" filter to redirect network traffic and access content from a host without explicit user permission.
What is the severity of CVE-2018-5166?
The severity of CVE-2018-5166 is high.
How can I fix CVE-2018-5166?
Update Firefox to version 60 or newer to fix CVE-2018-5166.