CVE-2018-12370 log

Source
Severity Low
Remote Yes
Type Access restriction bypass
Description
In the Reader View of Firefox before 61.0, SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Reader View is exited if loaded by a malicious site while Reader mode is active, bypassing CSRF protections.
Group Package Affected Fixed Severity Status Ticket
AVG-727 firefox 60.0.2-1 61.0-1 Critical Fixed
Date Advisory Group Package Severity Type
27 Jun 2018 ASA-201806-14 AVG-727 firefox Critical multiple issues
References
https://www.mozilla.org/en-US/security/advisories/mfsa2018-15/#CVE-2018-12370
https://bugzilla.mozilla.org/show_bug.cgi?id=1456652