SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-5142

This vulnerability affects Firefox < 59.

MEDIUM 5.3EPSS 1.21%

Does this matter?

Lower severity and a low EPSS score (1.21%). Track it; it rarely justifies an emergency change on its own.

Description

If Media Capture and Streams API permission is requested from documents with "data:" or "blob:" URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown protocol" as the requestee, leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox < 59.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
1.21% probability · 67th percentile
CISA KEV
Not listed
Affected
mozilla/firefox · canonical/ubuntu linux
Source
security@mozilla.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.