Your submission was sent successfully! Close

CVE-2018-12369

Published: 27 June 2018

WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain full browser permissions. This vulnerability affects Firefox ESR < 60.1 and Firefox < 61.

Priority

Medium

CVSS 3 base score: 9.8

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
artful
Released (61.0+build3-0ubuntu0.17.10.1)
bionic
Released (61.0+build3-0ubuntu0.18.04.1)
precise Does not exist

trusty Does not exist
(trusty was released [61.0+build3-0ubuntu0.14.04.2])
upstream
Released (61.0)
xenial
Released (61.0+build3-0ubuntu0.16.04.2)