A shared worker created from a "data:" URL in one tab can be shared by another tab with a different origin, bypassing the same-origin policy. This vulnerability affects Firefox < 59.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firefox-esrUpgrade thunderbirdUpgrade linux-thunderbirdUpgrade firefoxUpgrade seamonkeyUpgrade libxulUpgrade linux-firefoxUpgrade linux-seamonkeyUpgrade waterfox | Dec 10, 2025 | Mar 13, 2018 |
| Mfsa2018 06 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 59.0 | Jul 12, 2018 | Jun 11, 2018 |
| Suse | — | Upgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox | May 20, 2018 | Mar 14, 2018 |
| Ubuntu | — | Upgrade firefox | Apr 26, 2018 | Mar 14, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub