Beveiligingsadvies

CVE-2018-12395

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-02-28 18:00:00
Laatst bijgewerkt 2024-08-05 08:30:59
Toegewezen door mozilla
CVSS-score geen score
Status PUBLISHED

Beschrijving

By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain restrictions through domain fronting. This would allow access to domains that share a host that are otherwise restricted. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.