A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefox-esr | Apr 16, 2019 | Feb 28, 2019 |
| Amazon Linux Ami 2 | — | Upgrade thunderbird-debuginfoUpgrade thunderbird | Apr 27, 2020 | Feb 28, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 28, 2019 |
| Centos_linux | — | Upgrade firefox-debuginfoUpgrade thunderbird-debuginfoUpgrade thunderbirdUpgrade firefox | Dec 25, 2018 | Dec 11, 2018 |
| Debian | — | Upgrade firefox-esrUpgrade thunderbird | Dec 13, 2018 | Dec 11, 2018 |
| Freebsd | — | Upgrade seamonkeyUpgrade libxulUpgrade firefoxUpgrade thunderbirdUpgrade firefox-esrUpgrade linux-seamonkeyUpgrade linux-firefoxUpgrade waterfoxUpgrade linux-thunderbird | Dec 12, 2018 | Dec 11, 2018 |
| Gentoo Linux | — | Upgrade www-client/firefox.Upgrade www-client/firefox-bin. | Mar 11, 2019 | Feb 28, 2019 |
| Huawei Euleros 2_0_sp2 | — | Upgrade firefox | May 1, 2019 | Feb 28, 2019 |
| Huawei Euleros 2_0_sp3 | — | Upgrade firefox | May 30, 2019 | Feb 28, 2019 |
| Mfsa2018 29 | — | Upgrade to Mozilla Firefox version 64.0 | Dec 12, 2018 | Dec 11, 2018 |
| Mfsa2018 30 | — | Upgrade to Mozilla Firefox ESR version 60.4 | Dec 12, 2018 | Dec 11, 2018 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 60.4 | Jan 18, 2019 | Dec 21, 2018 |
| Oracle Solaris | — | Upgrade mail/thunderbird to version 60.6.1-11.4.9.0.1.2.0 on Solaris 11.4Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 60.6.1-11.4.9.0.1.2.0 on Solaris 11.4Upgrade web/browser/firefox to version 60.5.0-11.4.6.0.1.4.0 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 60.5.0-11.4.6.0.1.4.0 on Solaris 11.4 | Feb 20, 2019 | Feb 20, 2019 |
| Oracle_linux | — | Upgrade thunderbirdUpgrade firefox | Dec 18, 2018 | Dec 11, 2018 |
| Redhat_linux | — | Upgrade thunderbird-debuginfoUpgrade firefox-debuginfoUpgrade firefoxUpgrade thunderbird | Dec 18, 2018 | Dec 17, 2018 |
| Suse | — | Upgrade mozillathunderbird-translations-commonUpgrade mozilla-nssUpgrade mozilla-nspr-develUpgrade libsoftokn3-32bitUpgrade libsoftokn3Upgrade mozilla-nss-sysinitUpgrade mozilla-nspr-32bitUpgrade mozilla-nss-sysinit-32bitUpgrade mozilla-nsprUpgrade MozillaThunderbird-buildsymbolsUpgrade mozillafirefox-translations-commonUpgrade mozillafirefox-buildsymbolsUpgrade mozilla-nss-certsUpgrade mozilla-nss-32bitUpgrade mozillafirefox-translations-otherUpgrade mozilla-nss-certs-32bitUpgrade mozilla-nss-develUpgrade mozillathunderbird-translations-otherUpgrade mozillafirefoxUpgrade mozillathunderbirdUpgrade mozilla-nss-toolsUpgrade mozillafirefox-branding-upstreamUpgrade libfreebl3Upgrade libfreebl3-32bitUpgrade mozillafirefox-devel | Dec 14, 2018 | Dec 11, 2018 |
| Ubuntu | — | Upgrade firefoxUpgrade thunderbird | Jan 10, 2019 | Dec 11, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub