firefox: WebBrowserPersist uses incorrect origin information
Published Feb 28, 2019
6.5
MEDIUMCVSS 3.0
EPSS 1.32%
Description
The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of "Save Page As..." functionality. For example, a malicious page could recover a visitor's Windows username and NTLM hash by including resources otherwise unreachable to the malicious page, if they can convince the visitor to save the complete web page. Similarly, SameSite cookies are sent on cross-origin requests when the "Save Page As..." menu item is selected to save a page, which can result in saving the wrong version of resources based on those cookies. This vulnerability affects Firefox < 63.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<63
- Version
Configuration 2
- 14.04
- 16.04
- 18.04
- 18.10
No data.
Red Hat Enterprise Linux 6
firefox
Will not fix
Red Hat Enterprise Linux 7
firefox
Will not fix
Red Hat Enterprise Linux 8
firefox
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | firefox | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | firefox | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | firefox | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- http://www.securityfocus.com/bid/105721 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041944 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2018-12402 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1447087 x_refsource_CONFIRMIssue TrackingPermissions RequiredVendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1469916 x_refsource_CONFIRMIssue TrackingPermissions RequiredVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1696127 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2018-12402
- https://usn.ubuntu.com/3801-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-12402
- https://www.mozilla.org/en-US/security/advisories/mfsa2018-26/#CVE-2018-12402
- https://www.mozilla.org/security/advisories/mfsa2018-26/ x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/105721 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id/1041944 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2018-12402 | Vendor Advisory | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1447087 | x_refsource_CONFIRMIssue TrackingPermissions RequiredVendor Advisory | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1469916 | x_refsource_CONFIRMIssue TrackingPermissions RequiredVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1696127 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-12402 | ||
| https://usn.ubuntu.com/3801-1/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2018-12402 | ||
| https://www.mozilla.org/en-US/security/advisories/mfsa2018-26/#CVE-2018-12402 | ||
| https://www.mozilla.org/security/advisories/mfsa2018-26/ | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.