A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
                
            References
                    Configurations
                    Configuration 1 (hide)
                                
                                
  | 
                        
Configuration 2 (hide)
                                
                                
  | 
                        
Configuration 3 (hide)
                                
                                
  | 
                        
Configuration 4 (hide)
                                
                                
  | 
                        
Information
                Published : 2019-02-28 10:29
Updated : 2019-03-11 08:09
NVD link : CVE-2018-18494
Mitre link : CVE-2018-18494
JSON object : View
CWE
                
                    
                        
                        CWE-346
                        
            Origin Validation Error
Products Affected
                redhat
- enterprise_linux_desktop
 - enterprise_linux_server_aus
 - enterprise_linux_workstation
 - enterprise_linux_server_tus
 - enterprise_linux_server_eus
 - enterprise_linux_server
 
mozilla
- firefox_esr
 - thunderbird
 - firefox
 
canonical
- ubuntu_linux
 
debian
- debian_linux
 


