CVE-2018-12395 PUBLISHED

By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain restrictions through domain fronting. This would allow access to domains that share a host that are otherwise restricted. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.

EPSS 2.92% · 86.3th percentile

Risk Scores

EPSS Score
2.92%
86.3th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSmozjs380, 38.8.0~repack1-0ubuntu1, 38.8.0~repack1-0ubuntu3
Ubuntu:16.04:LTSfirefox44.0.1+build1-0ubuntu1, 44.0.2+build1-0ubuntu1, 45.0+build2-0ubuntu1
Ubuntu:20.04:LTSmozjs520, 52.9.1-1build1, 52.9.1-1ubuntu3
Ubuntu:18.04:LTSmozjs5252.9.1-0ubuntu0.18.04.1, 52.8.1-0ubuntu0.18.04.1, 52.3.1-7fakesync1
Ubuntu:14.04:LTSfirefox57.0.1+build2-0ubuntu0.14.04.1, 57.0.3+build1-0ubuntu0.14.04.1, 57.0.4+build1-0ubuntu0.14.04.1
Ubuntu:18.04:LTSfirefox62.0+build2-0ubuntu0.18.04.5, 62.0.3+build1-0ubuntu0.18.04.1, 62.0+build2-0ubuntu0.18.04.4

Timeline

References

Open in Interactive Console →