A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" for people who use the Firefox Multi-Account Containers Web Extension. This vulnerability affects Firefox < 68.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jul 23, 2019 |
| Freebsd | — | Upgrade seamonkeyUpgrade firefoxUpgrade thunderbirdUpgrade firefox-esrUpgrade linux-seamonkeyUpgrade libxulUpgrade linux-firefoxUpgrade waterfoxUpgrade linux-thunderbird | Jul 11, 2019 | Jul 9, 2019 |
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade www-client/firefox. | Aug 16, 2019 | Jul 23, 2019 |
| Mfsa2019 21 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 68.0 | Jul 10, 2019 | Jul 9, 2019 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 68.0Upgrade to the latest version of Mozilla Thunderbird | Sep 11, 2019 | Jul 23, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 23, 2019 |
| Suse | — | Upgrade firefox-libcairo-gobject2Upgrade firefox-atk-langUpgrade firefox-gtk3-toolsUpgrade mozilla-nss-certsUpgrade firefox-libatk-1_0-0Upgrade firefox-glib2-toolsUpgrade MozillaThunderbird-translations-commonUpgrade firefox-gtk3-immodule-amharicUpgrade mozilla-nssUpgrade firefox-gtk3-langUpgrade libfirefox-gio-2_0-0Upgrade mozilla-nss-toolsUpgrade firefox-gdk-pixbuf-langUpgrade firefox-libffi4Upgrade mozillafirefox-buildsymbolsUpgrade firefox-libcairo2Upgrade firefox-gdk-pixbuf-thumbnailerUpgrade firefox-libgtk-3-0Upgrade firefox-gdk-pixbuf-query-loadersUpgrade libfreebl3-32bitUpgrade MozillaFirefox-branding-SLEDUpgrade firefox-libpango-1_0-0Upgrade mozillafirefox-branding-upstreamUpgrade mozilla-nss-32bitUpgrade MozillaFirefox-translations-otherUpgrade libsoftokn3Upgrade firefox-gtk3-immodule-ximUpgrade mozilla-nss-certs-32bitUpgrade libfirefox-glib-2_0-0Upgrade enigmailUpgrade mozilla-nsprUpgrade mozillafirefox-branding-sleUpgrade firefox-libgdk_pixbuf-2_0-0Upgrade MozillaThunderbird-buildsymbolsUpgrade firefox-gtk3-immodule-thaiUpgrade firefox-glib2-langUpgrade libsoftokn3-32bitUpgrade libfreebl3Upgrade firefox-gtk3-dataUpgrade firefox-libffi7Upgrade firefox-gio-branding-upstreamUpgrade firefox-gtk3-branding-upstreamUpgrade mozilla-nspr-32bitUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefoxUpgrade MozillaThunderbirdUpgrade MozillaFirefox-develUpgrade libfirefox-gthread-2_0-0Upgrade libfirefox-gmodule-2_0-0Upgrade firefox-gtk3-immodule-multipressUpgrade mozilla-nss-develUpgrade libfirefox-gobject-2_0-0Upgrade firefox-gtk3-immodule-inuktitutUpgrade firefox-gtk3-immodules-tigrignaUpgrade firefox-libharfbuzz0Upgrade firefox-gtk3-immodule-vietnameseUpgrade MozillaThunderbird-translations-otherUpgrade mozilla-nspr-devel | Oct 8, 2019 | Jul 9, 2019 |
| Ubuntu | — | Upgrade firefox | Jul 13, 2019 | Jul 9, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub