When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing the domain of the current page. This vulnerability affects Firefox < 54.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 11, 2018 |
| Centos_linux | — | Upgrade firefoxUpgrade firefox-debuginfo | Jul 13, 2018 | Jun 15, 2017 |
| Freebsd | — | Upgrade linux-firefoxUpgrade linux-thunderbirdUpgrade firefox-esrUpgrade firefoxUpgrade linux-seamonkeyUpgrade seamonkeyUpgrade thunderbirdUpgrade libxul | Jun 16, 2017 | Jun 13, 2017 |
| Mfsa2017 15 | — | Upgrade to Mozilla Firefox version 54.0 | Jul 12, 2018 | Jun 11, 2018 |
| Oracle Solaris | — | Upgrade mail/thunderbird to version 52.3.0-0.175.3.24.0.4.0 on Solaris 11.3Upgrade web/data/firefox-bookmarks to version 52.3.0-0.175.3.24.0.2.0 on Solaris 11.3Upgrade web/browser/firefox to version 52.3.0-0.175.3.24.0.2.0 on Solaris 11.3Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 52.3.0-0.175.3.24.0.4.0 on Solaris 11.3Upgrade web/browser/firefox/plugin/firefox-java to version 52.3.0-0.175.3.24.0.2.0 on Solaris 11.3 | Aug 24, 2018 | Jun 11, 2018 |
| Oracle_linux | — | Upgrade firefox | Jul 4, 2018 | Apr 20, 2017 |
| Redhat_linux | — | Upgrade firefox-debuginfoUpgrade firefox | Jun 29, 2018 | Jun 15, 2017 |
| Ubuntu | — | Upgrade firefox | Jun 16, 2017 | Jun 15, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub