The "instanceof" operator can bypass the Xray wrapper mechanism. When called on web content from the browser itself or an extension the web content can provide its own result for that operator, possibly tricking the browser or extension into mishandling the element. This vulnerability affects Firefox < 56.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firefox-esrUpgrade linux-firefoxUpgrade seamonkeyUpgrade linux-seamonkeyUpgrade linux-thunderbirdUpgrade libxulUpgrade firefoxUpgrade thunderbird | Sep 29, 2017 | Sep 29, 2017 |
| Mfsa2017 21 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 56.0 | Jul 12, 2018 | Jun 11, 2018 |
| Suse | — | Upgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox | May 20, 2018 | Sep 28, 2017 |
| Ubuntu | — | Upgrade firefox | Oct 3, 2017 | Sep 28, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub