CVE-2018-5167: Input Validation
Last updated 24 July 2024
Other sources
The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:" links as active, clickable hyperlinks in their output. Web sites should not be able to directly link to internal chrome pages. Additionally, the JavaScript debugger will display "javascript:" links, which users could be tricked into clicking by malicious sites. This vulnerability affects Firefox < 60.
— Launchpad
The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display chrome: links as active, clickable hyperlinks in their output. Web sites should not be able to directly link to internal chrome pages. Additionally, the JavaScript debugger will display javascript: links, which users could be tricked into clicking by malicious sites.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5154
- CVE-2018-5155
- CVE-2018-5157
- CVE-2018-5158
- CVE-2018-5159
- CVE-2018-5160
- CVE-2018-5152
- CVE-2018-5153
- CVE-2018-5163
- CVE-2018-5164
- CVE-2018-5166
- CVE-2018-5167
- CVE-2018-5168
- CVE-2018-5169
- CVE-2018-5172
- CVE-2018-5173
- CVE-2018-5174
- CVE-2018-5175
- CVE-2018-5176
- CVE-2018-5177
- CVE-2018-5165
- CVE-2018-5180
- CVE-2018-5181
- CVE-2018-5182
- CVE-2018-5179
- CVE-2018-5151
- CVE-2018-5150
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-5167.
What software is affected by CVE-2018-5167?
Mozilla Firefox version up to 60.0 and Ubuntu with Firefox versions 60.0+, 14.04 LTS, 16.04 LTS, 17.10, 18.04 LTS are affected.
What is the severity level of CVE-2018-5167?
The severity level of CVE-2018-5167 is medium (4 out of 10).
What is the recommended remedy for CVE-2018-5167?
Update Mozilla Firefox to version 60.0 or higher.
Where can I find more information about CVE-2018-5167?
You can find more information about CVE-2018-5167 at the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1447969), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2018-11/), [SecurityFocus](http://www.securityfocus.com/bid/104139).