vulnerability

Red Hat: CVE-2017-5386: Critical: firefox security update (RHSA-2017:0190)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Jan 24, 2017
Added
Feb 3, 2017
Modified
Mar 3, 2021

Description

WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, leading to potential data disclosure or privilege escalation in affected extensions. This vulnerability affects Firefox ESR < 45.7 and Firefox < 51.

Solutions

redhat-upgrade-firefoxredhat-upgrade-firefox-debuginfo

References

    Title
    NEW

    Explore Exposure Command

    Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.