CVE-2018-12397 log

Source
Severity Medium
Remote Yes
Type Access restriction bypass
Description
A security issue has been found in Firefox versions prior to 63.0, where a WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened.
Group Package Affected Fixed Severity Status Ticket
AVG-787 firefox 62.0.3-2 63.0-1 Critical Fixed
Date Advisory Group Package Severity Description
24 Oct 2018 ASA-201810-14 AVG-787 firefox Critical multiple issues
References
https://www.mozilla.org/en-US/security/advisories/mfsa2018-26/#CVE-2018-12397
https://bugzilla.mozilla.org/show_bug.cgi?id=1487478