Back

HIGH

Mozilla: Local file can be displayed in noopener tab through drag and drop of hyperlink

Published Jun 11, 2018

Description

If a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a different child process the tab will open a local file corresponding to the dropped URL, contrary to policy. One way to make the target tab open more reliably in a separate process is to open it with the "noopener" keyword. This vulnerability affects Firefox < 60.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Jun 11, 2018
Updated Aug 5, 2024
Reserved Jan 3, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date May 9, 2018