WebExtensions can bypass normal restrictions in some circumstances and use "browser.tabs.executeScript" to inject scripts into contexts where this should not be allowed, such as pages from other WebExtensions or unprivileged "about:" pages. This vulnerability affects Firefox < 59.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/103386 | vdb entry third party advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=1431371 | permissions required |
http://www.securitytracker.com/id/1040514 | vdb entry third party advisory |
https://usn.ubuntu.com/3596-1/ | third party advisory vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2018-06/ | vendor advisory |