CVE-2018-5167 PUBLISHED

The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:" links as active, clickable hyperlinks in their output. Web sites should not be able to directly link to internal chrome pages. Additionally, the JavaScript debugger will display "javascript:" links, which users could be tricked into clicking by malicious sites. This vulnerability affects Firefox < 60.

EPSS 0.65% · 70.5th percentile

Risk Scores

EPSS Score
0.65%
70.5th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSfirefox0, 41.0.2+build2-0ubuntu1, 42.0+build2-0ubuntu1
Ubuntu:14.04:LTSfirefox48.0+build2-0ubuntu0.14.04.1, 49.0+build4-0ubuntu0.14.04.1, 49.0.2+build2-0ubuntu0.14.04.1
Ubuntu:18.04:LTSfirefox0, 56.0+build6-0ubuntu1, 57.0.1+build2-0ubuntu1

Timeline

References

Open in Interactive Console →