Origin Validation Error Affecting firefox package, versions <63.0-1
Snyk CVSS
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIANUNSTABLE-FIREFOX-422245
- published 28 Oct 2018
- disclosed 28 Feb 2019
Introduced: 28 Oct 2018
CVE-2018-12402 Open this link in a new tabHow to fix?
Upgrade Debian:unstable
firefox
to version 63.0-1 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream firefox
package and not the firefox
package as distributed by Debian
.
See How to fix?
for Debian:unstable
relevant fixed versions and status.
The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of "Save Page As..." functionality. For example, a malicious page could recover a visitor's Windows username and NTLM hash by including resources otherwise unreachable to the malicious page, if they can convince the visitor to save the complete web page. Similarly, SameSite cookies are sent on cross-origin requests when the "Save Page As..." menu item is selected to save a page, which can result in saving the wrong version of resources based on those cookies. This vulnerability affects Firefox < 63.
References
- https://security-tracker.debian.org/tracker/CVE-2018-12402
- https://www.mozilla.org/security/advisories/mfsa2018-26/
- https://bugzilla.mozilla.org/show_bug.cgi?id=1447087
- https://bugzilla.mozilla.org/show_bug.cgi?id=1469916
- http://www.securityfocus.com/bid/105721
- http://www.securitytracker.com/id/1041944
- http://people.ubuntu.com/~ubuntu-security/cve/CVE-2018-12402
- https://usn.ubuntu.com/3801-1/