CVE-2018-12402 Information
Description
The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of \Save Page As…\ functionality. For example a malicious page could recover a visitor’s Windows username and NTLM hash by including resources otherwise unreachable to the malicious page if they can convince the visitor to save the complete web page. Similarly SameSite cookies are sent on cross-origin requests when the \Save Page As…\ menu item is selected to save a page which can result in saving the wrong version of resources based on those cookies. This vulnerability affects Firefox 63.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Reference
http://www.securityfocus.com/bid/105721 http://www.securitytracker.com/id/1041944 https://bugzilla.mozilla.org/show_bug.cgi?id=1447087 https://bugzilla.mozilla.org/show_bug.cgi?id=1469916 https://usn.ubuntu.com/3801-1/ https://www.mozilla.org/security/advisories/mfsa2018-26/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
6.5
Share on: