Security Advisory

CVE-2017-5386

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-06-11 21:00:00
Last updated 2024-08-05 14:55:35
Assigner mozilla
CVSS score not scored
State PUBLISHED

Description

WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, leading to potential data disclosure or privilege escalation in affected extensions. This vulnerability affects Firefox ESR < 45.7 and Firefox < 51.