A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the private browsing tab and a normal tab. This could allow for the leaking of private information specific to the private browsing context. This issue is mitigated by the requirement that the user enter the Blob URL manually in order for the access violation to occur. This vulnerability affects Firefox < 58.
References
Link Resource
http://www.securityfocus.com/bid/102786 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1040270 VDB Entry Third Party Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1421099 Issue Tracking Permissions Required
https://usn.ubuntu.com/3544-1/ Third Party Advisory
https://www.mozilla.org/security/advisories/mfsa2018-02/ Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mozilla

Published: 2018-06-11T21:00:00

Updated: 2018-06-12T09:57:01

Reserved: 2018-01-03T00:00:00


Link: CVE-2018-5108

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-06-11T21:29:13.157

Modified: 2018-06-25T17:39:55.603


Link: CVE-2018-5108

JSON object: View

cve-icon Redhat Information

No data.

CWE