CVE-2018-12398 log

Source
Severity Medium
Remote Yes
Type Access restriction bypass
Description
A security issue has been found in Firefox versions prior to 63.0, where it is possible to inject stylesheets and bypass Content Security Policy (CSP) by using the reflected URL in some special resource URIs, such as chrome:.
Group Package Affected Fixed Severity Status Ticket
AVG-787 firefox 62.0.3-2 63.0-1 Critical Fixed
Date Advisory Group Package Severity Type
24 Oct 2018 ASA-201810-14 AVG-787 firefox Critical multiple issues
References
https://www.mozilla.org/en-US/security/advisories/mfsa2018-26/#CVE-2018-12398
https://bugzilla.mozilla.org/show_bug.cgi?id=1460538
https://bugzilla.mozilla.org/show_bug.cgi?id=1488061