A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefox-esr | Apr 16, 2019 | Feb 28, 2019 |
| Amazon Linux Ami 2 | — | Upgrade thunderbird-debuginfoUpgrade thunderbird | Apr 27, 2020 | Feb 28, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 28, 2019 |
| Centos_linux | — | Upgrade thunderbirdUpgrade firefoxUpgrade thunderbird-debuginfoUpgrade firefox-debuginfo | Dec 25, 2018 | Dec 11, 2018 |
| Debian | — | Upgrade thunderbirdUpgrade firefox-esr | Dec 13, 2018 | Dec 11, 2018 |
| Freebsd | — | Upgrade thunderbirdUpgrade linux-firefoxUpgrade waterfoxUpgrade linux-thunderbirdUpgrade firefox-esrUpgrade linux-seamonkeyUpgrade seamonkeyUpgrade firefoxUpgrade libxul | Dec 12, 2018 | Dec 11, 2018 |
| Gentoo Linux | — | Upgrade www-client/firefox.Upgrade www-client/firefox-bin. | Mar 11, 2019 | Feb 28, 2019 |
| Huawei Euleros 2_0_sp2 | — | Upgrade firefox | May 1, 2019 | Feb 28, 2019 |
| Huawei Euleros 2_0_sp3 | — | Upgrade firefox | May 30, 2019 | Feb 28, 2019 |
| Mfsa2018 29 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 64.0 | Dec 12, 2018 | Dec 11, 2018 |
| Mfsa2018 30 | — | Upgrade to Mozilla Firefox ESR version 60.4Upgrade to the latest version of Mozilla Firefox | Dec 12, 2018 | Dec 11, 2018 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 60.4 | Jan 18, 2019 | Dec 21, 2018 |
| Oracle Solaris | — | Upgrade web/data/firefox-bookmarks to version 60.5.0-11.4.6.0.1.4.0 on Solaris 11.4Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 60.6.1-11.4.9.0.1.2.0 on Solaris 11.4Upgrade web/browser/firefox to version 60.5.0-11.4.6.0.1.4.0 on Solaris 11.4Upgrade mail/thunderbird to version 60.6.1-11.4.9.0.1.2.0 on Solaris 11.4 | Feb 20, 2019 | Feb 20, 2019 |
| Oracle_linux | — | Upgrade thunderbirdUpgrade firefox | Dec 18, 2018 | Dec 11, 2018 |
| Redhat_linux | — | Upgrade firefox-debuginfoUpgrade thunderbird-debuginfoUpgrade thunderbirdUpgrade firefox | Dec 18, 2018 | Dec 17, 2018 |
| Suse | — | Upgrade MozillaThunderbirdUpgrade mozilla-nsprUpgrade mozilla-nspr-develUpgrade MozillaFirefox-translations-otherUpgrade libsoftokn3-32bitUpgrade mozilla-nss-sysinit-32bitUpgrade MozillaFirefox-develUpgrade mozilla-nssUpgrade MozillaThunderbird-translations-otherUpgrade libsoftokn3Upgrade mozilla-nspr-32bitUpgrade MozillaThunderbird-buildsymbolsUpgrade MozillaFirefox-translations-commonUpgrade mozilla-nss-sysinitUpgrade MozillaThunderbird-translations-commonUpgrade mozilla-nss-develUpgrade libfreebl3-32bitUpgrade mozilla-nss-32bitUpgrade mozillafirefox-buildsymbolsUpgrade mozilla-nss-certsUpgrade MozillaFirefoxUpgrade mozilla-nss-certs-32bitUpgrade libfreebl3Upgrade mozillafirefox-branding-upstreamUpgrade mozilla-nss-tools | Dec 14, 2018 | Dec 11, 2018 |
| Ubuntu | — | Upgrade firefoxUpgrade thunderbird | Jan 10, 2019 | Dec 11, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub