Opera before 12.11 allows remote attackers to determine the existence of arbitrary local files via vectors involving web script in an error page.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Opera_browser | Opera | * | 12.10 (including) |
| Opera_browser | Opera | 1.00 (including) | 1.00 (including) |
| Opera_browser | Opera | 2.00 (including) | 2.00 (including) |
| Opera_browser | Opera | 2.10 (including) | 2.10 (including) |
| Opera_browser | Opera | 2.10-beta1 (including) | 2.10-beta1 (including) |
| Opera_browser | Opera | 2.10-beta2 (including) | 2.10-beta2 (including) |
| Opera_browser | Opera | 2.10-beta3 (including) | 2.10-beta3 (including) |
| Opera_browser | Opera | 2.12 (including) | 2.12 (including) |
| Opera_browser | Opera | 3.00 (including) | 3.00 (including) |
| Opera_browser | Opera | 3.00-beta (including) | 3.00-beta (including) |
| Opera_browser | Opera | 3.10 (including) | 3.10 (including) |
| Opera_browser | Opera | 3.21 (including) | 3.21 (including) |
| Opera_browser | Opera | 3.50 (including) | 3.50 (including) |
| Opera_browser | Opera | 3.51 (including) | 3.51 (including) |
| Opera_browser | Opera | 3.60 (including) | 3.60 (including) |
| Opera_browser | Opera | 3.61 (including) | 3.61 (including) |
| Opera_browser | Opera | 3.62 (including) | 3.62 (including) |
| Opera_browser | Opera | 3.62-beta (including) | 3.62-beta (including) |
| Opera_browser | Opera | 4.00 (including) | 4.00 (including) |
| Opera_browser | Opera | 4.00-beta2 (including) | 4.00-beta2 (including) |
| Opera_browser | Opera | 4.00-beta3 (including) | 4.00-beta3 (including) |
| Opera_browser | Opera | 4.00-beta4 (including) | 4.00-beta4 (including) |
| Opera_browser | Opera | 4.00-beta5 (including) | 4.00-beta5 (including) |
| Opera_browser | Opera | 4.00-beta6 (including) | 4.00-beta6 (including) |
| Opera_browser | Opera | 4.01 (including) | 4.01 (including) |
| Opera_browser | Opera | 4.02 (including) | 4.02 (including) |
| Opera_browser | Opera | 5.0 (including) | 5.0 (including) |
| Opera_browser | Opera | 5.0-beta2 (including) | 5.0-beta2 (including) |
| Opera_browser | Opera | 5.0-beta3 (including) | 5.0-beta3 (including) |
| Opera_browser | Opera | 5.0-beta4 (including) | 5.0-beta4 (including) |
| Opera_browser | Opera | 5.0-beta5 (including) | 5.0-beta5 (including) |
| Opera_browser | Opera | 5.0-beta6 (including) | 5.0-beta6 (including) |
| Opera_browser | Opera | 5.0-beta7 (including) | 5.0-beta7 (including) |
| Opera_browser | Opera | 5.0-beta8 (including) | 5.0-beta8 (including) |
| Opera_browser | Opera | 5.02 (including) | 5.02 (including) |
| Opera_browser | Opera | 5.10 (including) | 5.10 (including) |
| Opera_browser | Opera | 5.11 (including) | 5.11 (including) |
| Opera_browser | Opera | 5.12 (including) | 5.12 (including) |
| Opera_browser | Opera | 6.0 (including) | 6.0 (including) |
| Opera_browser | Opera | 6.0-beta1 (including) | 6.0-beta1 (including) |
| Opera_browser | Opera | 6.0-beta2 (including) | 6.0-beta2 (including) |
| Opera_browser | Opera | 6.0-beta3 (including) | 6.0-beta3 (including) |
| Opera_browser | Opera | 6.0-tp1 (including) | 6.0-tp1 (including) |
| Opera_browser | Opera | 6.0-tp2 (including) | 6.0-tp2 (including) |
| Opera_browser | Opera | 6.0-tp3 (including) | 6.0-tp3 (including) |
| Opera_browser | Opera | 6.1 (including) | 6.1 (including) |
| Opera_browser | Opera | 6.01 (including) | 6.01 (including) |
| Opera_browser | Opera | 6.1-beta1 (including) | 6.1-beta1 (including) |
| Opera_browser | Opera | 6.02 (including) | 6.02 (including) |
| Opera_browser | Opera | 6.03 (including) | 6.03 (including) |
| Opera_browser | Opera | 6.04 (including) | 6.04 (including) |
| Opera_browser | Opera | 6.05 (including) | 6.05 (including) |
| Opera_browser | Opera | 6.06 (including) | 6.06 (including) |
| Opera_browser | Opera | 6.11 (including) | 6.11 (including) |
| Opera_browser | Opera | 6.12 (including) | 6.12 (including) |
| Opera_browser | Opera | 7.0 (including) | 7.0 (including) |
| Opera_browser | Opera | 7.0-beta1 (including) | 7.0-beta1 (including) |
| Opera_browser | Opera | 7.0-beta1_v2 (including) | 7.0-beta1_v2 (including) |
| Opera_browser | Opera | 7.0-beta2 (including) | 7.0-beta2 (including) |
| Opera_browser | Opera | 7.01 (including) | 7.01 (including) |
| Opera_browser | Opera | 7.02 (including) | 7.02 (including) |
| Opera_browser | Opera | 7.03 (including) | 7.03 (including) |
| Opera_browser | Opera | 7.10 (including) | 7.10 (including) |
| Opera_browser | Opera | 7.10-beta1 (including) | 7.10-beta1 (including) |
| Opera_browser | Opera | 7.11 (including) | 7.11 (including) |
| Opera_browser | Opera | 7.11-beta2 (including) | 7.11-beta2 (including) |
| Opera_browser | Opera | 7.20 (including) | 7.20 (including) |
| Opera_browser | Opera | 7.20-beta7 (including) | 7.20-beta7 (including) |
| Opera_browser | Opera | 7.21 (including) | 7.21 (including) |
| Opera_browser | Opera | 7.22 (including) | 7.22 (including) |
| Opera_browser | Opera | 7.23 (including) | 7.23 (including) |
| Opera_browser | Opera | 7.50 (including) | 7.50 (including) |
| Opera_browser | Opera | 7.50-beta1 (including) | 7.50-beta1 (including) |
| Opera_browser | Opera | 7.51 (including) | 7.51 (including) |
| Opera_browser | Opera | 7.52 (including) | 7.52 (including) |
| Opera_browser | Opera | 7.53 (including) | 7.53 (including) |
| Opera_browser | Opera | 7.54 (including) | 7.54 (including) |
| Opera_browser | Opera | 7.54-update1 (including) | 7.54-update1 (including) |
| Opera_browser | Opera | 7.54-update2 (including) | 7.54-update2 (including) |
| Opera_browser | Opera | 7.60 (including) | 7.60 (including) |
| Opera_browser | Opera | 8.0 (including) | 8.0 (including) |
| Opera_browser | Opera | 8.0-beta1 (including) | 8.0-beta1 (including) |
| Opera_browser | Opera | 8.0-beta2 (including) | 8.0-beta2 (including) |
| Opera_browser | Opera | 8.0-beta3 (including) | 8.0-beta3 (including) |
| Opera_browser | Opera | 8.01 (including) | 8.01 (including) |
| Opera_browser | Opera | 8.02 (including) | 8.02 (including) |
| Opera_browser | Opera | 8.50 (including) | 8.50 (including) |
| Opera_browser | Opera | 8.51 (including) | 8.51 (including) |
| Opera_browser | Opera | 8.52 (including) | 8.52 (including) |
| Opera_browser | Opera | 8.53 (including) | 8.53 (including) |
| Opera_browser | Opera | 8.54 (including) | 8.54 (including) |
| Opera_browser | Opera | 9.0 (including) | 9.0 (including) |
| Opera_browser | Opera | 9.0-beta1 (including) | 9.0-beta1 (including) |
| Opera_browser | Opera | 9.0-beta2 (including) | 9.0-beta2 (including) |
| Opera_browser | Opera | 9.01 (including) | 9.01 (including) |
| Opera_browser | Opera | 9.02 (including) | 9.02 (including) |
| Opera_browser | Opera | 9.10 (including) | 9.10 (including) |
| Opera_browser | Opera | 9.12 (including) | 9.12 (including) |
| Opera_browser | Opera | 9.20 (including) | 9.20 (including) |
| Opera_browser | Opera | 9.20-beta1 (including) | 9.20-beta1 (including) |
| Opera_browser | Opera | 9.21 (including) | 9.21 (including) |
| Opera_browser | Opera | 9.22 (including) | 9.22 (including) |
| Opera_browser | Opera | 9.23 (including) | 9.23 (including) |
| Opera_browser | Opera | 9.24 (including) | 9.24 (including) |
| Opera_browser | Opera | 9.25 (including) | 9.25 (including) |
| Opera_browser | Opera | 9.26 (including) | 9.26 (including) |
| Opera_browser | Opera | 9.27 (including) | 9.27 (including) |
| Opera_browser | Opera | 9.50 (including) | 9.50 (including) |
| Opera_browser | Opera | 9.50-beta1 (including) | 9.50-beta1 (including) |
| Opera_browser | Opera | 9.50-beta2 (including) | 9.50-beta2 (including) |
| Opera_browser | Opera | 9.51 (including) | 9.51 (including) |
| Opera_browser | Opera | 9.52 (including) | 9.52 (including) |
| Opera_browser | Opera | 9.60 (including) | 9.60 (including) |
| Opera_browser | Opera | 9.60-beta1 (including) | 9.60-beta1 (including) |
| Opera_browser | Opera | 9.61 (including) | 9.61 (including) |
| Opera_browser | Opera | 9.62 (including) | 9.62 (including) |
| Opera_browser | Opera | 9.63 (including) | 9.63 (including) |
| Opera_browser | Opera | 9.64 (including) | 9.64 (including) |
| Opera_browser | Opera | 10.00 (including) | 10.00 (including) |
| Opera_browser | Opera | 10.00-alpha (including) | 10.00-alpha (including) |
| Opera_browser | Opera | 10.00-beta1 (including) | 10.00-beta1 (including) |
| Opera_browser | Opera | 10.00-beta2 (including) | 10.00-beta2 (including) |
| Opera_browser | Opera | 10.00-beta3 (including) | 10.00-beta3 (including) |
| Opera_browser | Opera | 10.01 (including) | 10.01 (including) |
| Opera_browser | Opera | 10.10 (including) | 10.10 (including) |
| Opera_browser | Opera | 10.10-beta1 (including) | 10.10-beta1 (including) |
| Opera_browser | Opera | 10.11 (including) | 10.11 (including) |
| Opera_browser | Opera | 10.20-alpha (including) | 10.20-alpha (including) |
| Opera_browser | Opera | 10.50 (including) | 10.50 (including) |
| Opera_browser | Opera | 10.50-beta1 (including) | 10.50-beta1 (including) |
| Opera_browser | Opera | 10.50-beta2 (including) | 10.50-beta2 (including) |
| Opera_browser | Opera | 10.51 (including) | 10.51 (including) |
| Opera_browser | Opera | 10.52 (including) | 10.52 (including) |
| Opera_browser | Opera | 10.52-beta1 (including) | 10.52-beta1 (including) |
| Opera_browser | Opera | 10.52-beta2 (including) | 10.52-beta2 (including) |
| Opera_browser | Opera | 10.53 (including) | 10.53 (including) |
| Opera_browser | Opera | 10.53-b (including) | 10.53-b (including) |
| Opera_browser | Opera | 10.53-beta1 (including) | 10.53-beta1 (including) |
| Opera_browser | Opera | 10.54 (including) | 10.54 (including) |
| Opera_browser | Opera | 10.60 (including) | 10.60 (including) |
| Opera_browser | Opera | 10.60-alpha (including) | 10.60-alpha (including) |
| Opera_browser | Opera | 10.60-beta1 (including) | 10.60-beta1 (including) |
| Opera_browser | Opera | 10.61 (including) | 10.61 (including) |
| Opera_browser | Opera | 10.62 (including) | 10.62 (including) |
| Opera_browser | Opera | 10.63 (including) | 10.63 (including) |
| Opera_browser | Opera | 11.00 (including) | 11.00 (including) |
| Opera_browser | Opera | 11.00-beta (including) | 11.00-beta (including) |
| Opera_browser | Opera | 11.01 (including) | 11.01 (including) |
| Opera_browser | Opera | 11.10 (including) | 11.10 (including) |
| Opera_browser | Opera | 11.10-beta (including) | 11.10-beta (including) |
| Opera_browser | Opera | 11.11 (including) | 11.11 (including) |
| Opera_browser | Opera | 11.50 (including) | 11.50 (including) |
| Opera_browser | Opera | 11.50-beta (including) | 11.50-beta (including) |
| Opera_browser | Opera | 11.51 (including) | 11.51 (including) |
| Opera_browser | Opera | 11.52 (including) | 11.52 (including) |
| Opera_browser | Opera | 11.52.1100 (including) | 11.52.1100 (including) |
| Opera_browser | Opera | 11.60 (including) | 11.60 (including) |
| Opera_browser | Opera | 11.60-beta (including) | 11.60-beta (including) |
| Opera_browser | Opera | 11.61 (including) | 11.61 (including) |
| Opera_browser | Opera | 11.62 (including) | 11.62 (including) |
| Opera_browser | Opera | 11.64 (including) | 11.64 (including) |
| Opera_browser | Opera | 11.65 (including) | 11.65 (including) |
| Opera_browser | Opera | 11.66 (including) | 11.66 (including) |
| Opera_browser | Opera | 12.00 (including) | 12.00 (including) |
| Opera_browser | Opera | 12.00-beta (including) | 12.00-beta (including) |
| Opera_browser | Opera | 12.01 (including) | 12.01 (including) |
| Opera_browser | Opera | 12.02 (including) | 12.02 (including) |
| Opera_browser | Opera | 12.10-beta (including) | 12.10-beta (including) |
There are many different kinds of mistakes that introduce information exposures. The severity of the error can range widely, depending on the context in which the product operates, the type of sensitive information that is revealed, and the benefits it may provide to an attacker. Some kinds of sensitive information include:
Information might be sensitive to different parties, each of which may have their own expectations for whether the information should be protected. These parties include:
Information exposures can occur in different ways:
It is common practice to describe any loss of confidentiality as an “information exposure,” but this can lead to overuse of CWE-200 in CWE mapping. From the CWE perspective, loss of confidentiality is a technical impact that can arise from dozens of different weaknesses, such as insecure file permissions or out-of-bounds read. CWE-200 and its lower-level descendants are intended to cover the mistakes that occur in behaviors that explicitly manage, store, transfer, or cleanse sensitive information.