CVE-2017-5389
WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site.
Does this matter?
Lower severity and a low EPSS score (0.93%). Track it; it rarely justifies an emergency change on its own.
Description
WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 51.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.93% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- mozilla/firefox
- Source
- security@mozilla.org
References
- http://www.securityfocus.com/bid/95763Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037693Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1308688Exploit, Issue Tracking, Patch, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-01/Vendor Advisory
- http://www.securityfocus.com/bid/95763Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037693Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1308688Exploit, Issue Tracking, Patch, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-01/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.