CVE-2018-5175: XSS
A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" policy of "'strict-dynamic'". If a target website contains an HTML injection flaw an attacker could inject a reference to a copy of the "require.js" library that is part of Firefox's Developer Tools, and then use a known technique using that library to bypass the CSP restrictions on executing injected scripts. This vulnerability affects Firefox < 60.
Other sources
A mechanism to bypass Content Security Policy (CSP) protections on sites that have a script-src policy of 'strict-dynamic'. If a target website contains an HTML injection flaw an attacker could inject a reference to a copy of the require.js library that is part of Firefox’s Developer Tools, and then use a known technique using that library to bypass the CSP restrictions on executing injected scripts.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5154
- CVE-2018-5155
- CVE-2018-5157
- CVE-2018-5158
- CVE-2018-5159
- CVE-2018-5160
- CVE-2018-5152
- CVE-2018-5153
- CVE-2018-5163
- CVE-2018-5164
- CVE-2018-5166
- CVE-2018-5167
- CVE-2018-5168
- CVE-2018-5169
- CVE-2018-5172
- CVE-2018-5173
- CVE-2018-5174
- CVE-2018-5175
- CVE-2018-5176
- CVE-2018-5177
- CVE-2018-5165
- CVE-2018-5180
- CVE-2018-5181
- CVE-2018-5182
- CVE-2018-5179
- CVE-2018-5151
- CVE-2018-5150
Frequently Asked Questions
What is CVE-2018-5175?
CVE-2018-5175 is a vulnerability that allows bypassing Content Security Policy (CSP) protections on websites with a 'strict-dynamic' policy.
Which software is affected by CVE-2018-5175?
Mozilla Firefox versions up to 60.0, Ubuntu with Firefox versions up to 60.0, and various versions of Canonical Ubuntu Linux are affected by CVE-2018-5175.
What is the severity rating of CVE-2018-5175?
The severity rating of CVE-2018-5175 is medium with a CVSS score of 6.1.
How can I fix CVE-2018-5175?
To fix CVE-2018-5175, update your Mozilla Firefox browser to version 60.0 or higher, or update Ubuntu or Canonical Ubuntu Linux to versions that include Firefox 60.0 or higher.
Where can I find more information about CVE-2018-5175?
You can find more information about CVE-2018-5175 at the following references: <ul><li>https://bugzilla.mozilla.org/show_bug.cgi?id=1432358</li><li>https://www.mozilla.org/en-US/security/advisories/mfsa2018-11/</li><li>http://www.securityfocus.com/bid/104139</li></ul>