Back

MEDIUM

Mozilla: Same-origin policy violation using meta refresh and performance.getEntries to steal cross-origin URLs

Published Feb 28, 2019

Description

A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Feb 28, 2019
Updated Aug 5, 2024
Reserved Oct 19, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 5, 2018