CVE-2018-5181: Infoleak
If a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a different child process the tab will open a local file corresponding to the dropped URL, contrary to policy. One way to make the target tab open more reliably in a separate process is to open it with the "noopener" keyword. This vulnerability affects Firefox < 60.
Other sources
If a URL using the file: protocol is dragged and dropped onto an open tab that is running in a different child process the tab will open a local file corresponding to the dropped URL, contrary to policy. One way to make the target tab open more reliably in a separate process is to open it with the noopener keyword.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5154
- CVE-2018-5155
- CVE-2018-5157
- CVE-2018-5158
- CVE-2018-5159
- CVE-2018-5160
- CVE-2018-5152
- CVE-2018-5153
- CVE-2018-5163
- CVE-2018-5164
- CVE-2018-5166
- CVE-2018-5167
- CVE-2018-5168
- CVE-2018-5169
- CVE-2018-5172
- CVE-2018-5173
- CVE-2018-5174
- CVE-2018-5175
- CVE-2018-5176
- CVE-2018-5177
- CVE-2018-5165
- CVE-2018-5180
- CVE-2018-5181
- CVE-2018-5182
- CVE-2018-5179
- CVE-2018-5151
- CVE-2018-5150
Frequently Asked Questions
What is CVE-2018-5181?
CVE-2018-5181 is a vulnerability where if a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a different child process in Mozilla Firefox, the tab will open a local file even if it goes against policy.
How does CVE-2018-5181 affect Mozilla Firefox?
CVE-2018-5181 affects Mozilla Firefox versions up to and excluding 60.0, allowing a local file to be opened contrary to policy when a URL with the "file:" protocol is dragged and dropped onto an open tab running in a different process.
What is the severity level of CVE-2018-5181?
The severity level of CVE-2018-5181 is high, with a CVSS score of 7.5.
How can I fix CVE-2018-5181 in Mozilla Firefox?
To fix CVE-2018-5181 in Mozilla Firefox, update your browser to version 60.0 or higher.
Where can I find more information about CVE-2018-5181?
You can find more information about CVE-2018-5181 on the Mozilla Bugzilla website (https://bugzilla.mozilla.org/show_bug.cgi?id=1424107), the Mozilla Security Advisories website (https://www.mozilla.org/en-US/security/advisories/mfsa2018-11/), and the SecurityFocus website (http://www.securityfocus.com/bid/104139).