CVE Database
/

CVE-2018-5108

Back to search

CVE-2018-5108

Published: Jun 11, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the private browsing tab and a normal tab. This could allow for the leaking of private information specific to the private browsing context. This issue is mitigated by the requirement that the user enter the Blob URL manually in order for the access violation to occur. This vulnerability affects Firefox < 58.

VendorProductVersions

Mozilla

Firefox

affected
unspecified - < 58

References

1040270
vdb-entry
x_refsource_SECTRACK
USN-3544-1
vendor-advisory
x_refsource_UBUNTU
102786
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now