CVE-2017-7787

Source
Severity High
Remote Yes
Type Same-origin policy bypass
Description
Same-origin policy protections can be bypassed in firefox < 55.0 and thunderbird < 52.3, on pages with embedded iframes during page reloads, allowing the iframes to access content on the top level page and leading to information disclosure.
Group Package Affected Fixed Severity Status Ticket
AVG-385 thunderbird 52.2.1-1 52.3.0-1 Critical Fixed
AVG-375 firefox 54.0.1-1 55.0-1 Critical Fixed
Date Advisory Group Package Severity Description
10 Aug 2017 ASA-201708-3 AVG-375 firefox Critical multiple issues
23 Aug 2017 ASA-201708-18 AVG-385 thunderbird Critical multiple issues
References
https://www.mozilla.org/en-US/security/advisories/mfsa2017-18/#CVE-2017-7787
https://bugzilla.mozilla.org/show_bug.cgi?id=1322896