CVE Vulnerabilities

CVE-2018-5142

Published: Jun 11, 2018 | Modified: Oct 03, 2019
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

If Media Capture and Streams API permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states Unknown protocol as the requestee, leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox < 59.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla * 59.0 (excluding)

References