CVE-2018-5114 PUBLISHED

If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document is closed. Network requests correctly use the changed HttpOnly cookie. This vulnerability affects Firefox < 58.

EPSS 0.47% · 64.4th percentile

Risk Scores

EPSS Score
0.47%
64.4th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSfirefox57.0.1+build2-0ubuntu1, 56.0+build6-0ubuntu1, 0
Ubuntu:14.04:LTSfirefox28.0~b2+build1-0ubuntu2, 28.0+build1-0ubuntu1, 28.0+build2-0ubuntu1
Ubuntu:16.04:LTSfirefox44.0+build3-0ubuntu2, 44.0.1+build1-0ubuntu1, 44.0.2+build1-0ubuntu1

Timeline

References

Open in Interactive Console →