SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-5168

Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element.

MEDIUM 5.3EPSS 2.38%

Does this matter?

Lower severity and a low EPSS score (2.38%). Track it; it rarely justifies an emergency change on its own.

Description

Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
2.38% probability · 83th percentile
CISA KEV
Not listed
Affected
debian/debian linux · mozilla/firefox · mozilla/thunderbird · mozilla/thunderbird esr · canonical/ubuntu linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation
Source
security@mozilla.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.