Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mozilla

Published: 2018-06-11T21:00:00

Updated: 2018-10-20T09:57:01

Reserved: 2018-01-03T00:00:00


Link: CVE-2018-5157

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-06-11T21:29:15.233

Modified: 2019-03-13T13:44:13.607


Link: CVE-2018-5157

JSON object: View

cve-icon Redhat Information

No data.