A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" for people who use the Firefox Multi-Account Containers Web Extension. This vulnerability affects Firefox < 68.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jul 23, 2019 |
| Freebsd | — | Upgrade firefox-esrUpgrade linux-seamonkeyUpgrade thunderbirdUpgrade firefoxUpgrade seamonkeyUpgrade libxulUpgrade linux-firefoxUpgrade waterfoxUpgrade linux-thunderbird | Jul 11, 2019 | Jul 9, 2019 |
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade www-client/firefox. | Aug 16, 2019 | Jul 23, 2019 |
| Mfsa2019 21 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 68.0 | Jul 10, 2019 | Jul 9, 2019 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 68.0 | Sep 11, 2019 | Jul 23, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 23, 2019 |
| Suse | — | Upgrade libsoftokn3-32bitUpgrade firefox-gtk3-immodules-tigrignaUpgrade firefox-libffi7Upgrade firefox-glib2-langUpgrade mozilla-nss-develUpgrade firefox-gtk3-immodule-inuktitutUpgrade mozilla-nspr-32bitUpgrade MozillaThunderbird-translations-otherUpgrade MozillaThunderbird-buildsymbolsUpgrade MozillaThunderbirdUpgrade libfirefox-gmodule-2_0-0Upgrade firefox-gtk3-immodule-thaiUpgrade enigmailUpgrade MozillaFirefoxUpgrade mozillafirefox-branding-sleUpgrade mozilla-nsprUpgrade firefox-gtk3-immodule-multipressUpgrade firefox-gtk3-immodule-vietnameseUpgrade firefox-libharfbuzz0Upgrade firefox-gtk3-branding-upstreamUpgrade firefox-libgdk_pixbuf-2_0-0Upgrade libfreebl3Upgrade firefox-gtk3-dataUpgrade mozilla-nspr-develUpgrade libfirefox-gobject-2_0-0Upgrade firefox-gio-branding-upstreamUpgrade libfirefox-gthread-2_0-0Upgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-develUpgrade mozillafirefox-branding-upstreamUpgrade mozilla-nssUpgrade MozillaFirefox-translations-commonUpgrade firefox-gtk3-langUpgrade mozilla-nss-certs-32bitUpgrade MozillaThunderbird-translations-commonUpgrade firefox-libcairo-gobject2Upgrade mozillafirefox-buildsymbolsUpgrade firefox-gdk-pixbuf-langUpgrade firefox-gdk-pixbuf-query-loadersUpgrade mozilla-nss-toolsUpgrade firefox-libpango-1_0-0Upgrade firefox-gtk3-immodule-amharicUpgrade firefox-libgtk-3-0Upgrade mozilla-nss-32bitUpgrade libsoftokn3Upgrade firefox-libffi4Upgrade firefox-gtk3-immodule-ximUpgrade libfreebl3-32bitUpgrade libfirefox-gio-2_0-0Upgrade MozillaFirefox-branding-SLEDUpgrade libfirefox-glib-2_0-0Upgrade firefox-libcairo2Upgrade firefox-gdk-pixbuf-thumbnailerUpgrade firefox-glib2-toolsUpgrade firefox-gtk3-toolsUpgrade firefox-libatk-1_0-0Upgrade mozilla-nss-certsUpgrade firefox-atk-lang | Oct 8, 2019 | Jul 9, 2019 |
| Ubuntu | — | Upgrade firefox | Jul 13, 2019 | Jul 9, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub