A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" for people who use the Firefox Multi-Account Containers Web Extension. This vulnerability affects Firefox < 68.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jul 23, 2019 |
| Freebsd | — | Upgrade linux-seamonkeyUpgrade seamonkeyUpgrade thunderbirdUpgrade firefoxUpgrade firefox-esrUpgrade linux-thunderbirdUpgrade libxulUpgrade linux-firefoxUpgrade waterfox | Jul 11, 2019 | Jul 9, 2019 |
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade www-client/firefox. | Aug 16, 2019 | Jul 23, 2019 |
| Mfsa2019 21 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 68.0 | Jul 10, 2019 | Jul 9, 2019 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 68.0Upgrade to the latest version of Mozilla Thunderbird | Sep 11, 2019 | Jul 23, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 23, 2019 |
| Suse | — | Upgrade MozillaFirefoxUpgrade firefox-libffi7Upgrade mozilla-nspr-develUpgrade enigmailUpgrade libfreebl3Upgrade firefox-gtk3-immodule-vietnameseUpgrade firefox-gtk3-immodule-thaiUpgrade firefox-libharfbuzz0Upgrade MozillaThunderbirdUpgrade firefox-libgdk_pixbuf-2_0-0Upgrade firefox-gio-branding-upstreamUpgrade firefox-gtk3-dataUpgrade mozillafirefox-branding-sleUpgrade firefox-glib2-langUpgrade mozilla-nsprUpgrade libfirefox-gmodule-2_0-0Upgrade firefox-gtk3-branding-upstreamUpgrade MozillaThunderbird-buildsymbolsUpgrade MozillaFirefox-develUpgrade libsoftokn3-32bitUpgrade firefox-gtk3-immodule-multipressUpgrade firefox-gtk3-immodules-tigrignaUpgrade libfirefox-gobject-2_0-0Upgrade mozilla-nss-develUpgrade firefox-gtk3-immodule-inuktitutUpgrade MozillaThunderbird-translations-otherUpgrade libfirefox-gthread-2_0-0Upgrade firefox-gdk-pixbuf-langUpgrade mozilla-nspr-32bitUpgrade mozillafirefox-buildsymbolsUpgrade firefox-libpango-1_0-0Upgrade MozillaFirefox-translations-commonUpgrade firefox-libcairo-gobject2Upgrade firefox-atk-langUpgrade mozilla-nss-toolsUpgrade firefox-libcairo2Upgrade firefox-gdk-pixbuf-thumbnailerUpgrade libfirefox-glib-2_0-0Upgrade firefox-gdk-pixbuf-query-loadersUpgrade libfirefox-gio-2_0-0Upgrade firefox-libgtk-3-0Upgrade firefox-glib2-toolsUpgrade firefox-gtk3-toolsUpgrade firefox-gtk3-immodule-amharicUpgrade MozillaThunderbird-translations-commonUpgrade libsoftokn3Upgrade mozilla-nss-32bitUpgrade MozillaFirefox-translations-otherUpgrade libfreebl3-32bitUpgrade mozilla-nssUpgrade mozillafirefox-branding-upstreamUpgrade firefox-libffi4Upgrade firefox-gtk3-immodule-ximUpgrade mozilla-nss-certs-32bitUpgrade MozillaFirefox-branding-SLEDUpgrade firefox-gtk3-langUpgrade firefox-libatk-1_0-0Upgrade mozilla-nss-certs | Oct 8, 2019 | Jul 9, 2019 |
| Ubuntu | — | Upgrade firefox | Jul 13, 2019 | Jul 9, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub