NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect to the target site. This allows for a malicious site to engage in cross-site request forgery (CSRF) attacks. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
http://www.securityfocus.com/bid/104560
http://www.securitytracker.com/id/1041193
https://access.redhat.com/errata/RHSA-2018:2112
https://access.redhat.com/errata/RHSA-2018:2113
https://access.redhat.com/errata/RHSA-2018:2251
https://access.redhat.com/errata/RHSA-2018:2252
https://bugzilla.mozilla.org/show_bug.cgi?id=1436241
https://lists.debian.org/debian-lts-announce/2018/06/msg00014.html
https://lists.debian.org/debian-lts-announce/2018/07/msg00013.html
https://security.gentoo.org/glsa/201810-01
https://security.gentoo.org/glsa/201811-13
https://usn.ubuntu.com/3705-1/
https://usn.ubuntu.com/3714-1/
https://www.debian.org/security/2018/dsa-4235
https://www.debian.org/security/2018/dsa-4244
https://www.mozilla.org/security/advisories/mfsa2018-15/
https://www.mozilla.org/security/advisories/mfsa2018-16/
https://www.mozilla.org/security/advisories/mfsa2018-17/
Source: MITRE
Published: 2018-10-18
Updated: 2018-12-03
Type: CWE-352
Base Score: 6.8
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
Impact Score: 6.4
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 8.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 2.8
Severity: HIGH
OR
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
OR
OR
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
OR
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
127413 | NewStart CGSL MAIN 4.05 : thunderbird Multiple Vulnerabilities (NS-SA-2019-0145) | Nessus | NewStart CGSL Local Security Checks | high |
127404 | NewStart CGSL MAIN 4.05 : firefox Multiple Vulnerabilities (NS-SA-2019-0141) | Nessus | NewStart CGSL Local Security Checks | high |
127208 | NewStart CGSL CORE 5.04 / MAIN 5.04 : thunderbird Multiple Vulnerabilities (NS-SA-2019-0037) | Nessus | NewStart CGSL Local Security Checks | high |
127198 | NewStart CGSL CORE 5.04 / MAIN 5.04 : firefox Multiple Vulnerabilities (NS-SA-2019-0032) | Nessus | NewStart CGSL Local Security Checks | high |
123293 | openSUSE Security Update : MozillaThunderbird (openSUSE-2019-680) | Nessus | SuSE Local Security Checks | high |
123288 | openSUSE Security Update : MozillaThunderbird (openSUSE-2019-664) | Nessus | SuSE Local Security Checks | high |
123263 | openSUSE Security Update : seamonkey (openSUSE-2019-602) | Nessus | SuSE Local Security Checks | high |
123208 | openSUSE Security Update : Mozilla Thunderbird (openSUSE-2019-503) | Nessus | SuSE Local Security Checks | high |
123203 | openSUSE Security Update : MozillaFirefox (openSUSE-2019-494) | Nessus | SuSE Local Security Checks | high |
120074 | SUSE SLED15 / SLES15 Security Update : MozillaFirefox (SUSE-SU-2018:2298-1) | Nessus | SuSE Local Security Checks | high |
119133 | GLSA-201811-13 : Mozilla Thunderbird: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | high |
118279 | SUSE SLES12 Security Update : MozillaFirefox (SUSE-SU-2018:2322-2) | Nessus | SuSE Local Security Checks | high |
117987 | openSUSE Security Update : MozillaThunderbird (openSUSE-2018-1139) | Nessus | SuSE Local Security Checks | high |
117894 | GLSA-201810-01 : Mozilla Firefox: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | high |
117383 | openSUSE Security Update : MozillaThunderbird (openSUSE-2018-994) | Nessus | SuSE Local Security Checks | high |
112086 | Amazon Linux 2 : thunderbird (ALAS-2018-1061) | Nessus | Amazon Linux Local Security Checks | high |
700341 | Mozilla Firefox ESR < 60.1 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | high |
700339 | Mozilla Firefox ESR < 52.9 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | high |
700330 | Mozilla Firefox < 61 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | high |
111981 | Mozilla Thunderbird < 60.0 Multiple Vulnerabilities | Nessus | Windows | high |
111980 | Mozilla Thunderbird < 60.0 Multiple Vulnerabilities (macOS) | Nessus | MacOS X Local Security Checks | high |
111780 | openSUSE Security Update : seamonkey (openSUSE-2018-867) | Nessus | SuSE Local Security Checks | high |
111745 | SUSE SLES11 Security Update : MozillaFirefox (SUSE-SU-2018:2325-1) | Nessus | SuSE Local Security Checks | high |
111743 | SUSE SLED12 / SLES12 Security Update : MozillaFirefox (SUSE-SU-2018:2322-1) | Nessus | SuSE Local Security Checks | high |
111356 | CentOS 6 : thunderbird (CESA-2018:2251) | Nessus | CentOS Local Security Checks | high |
111344 | Scientific Linux Security Update : thunderbird on SL7.x x86_64 (20180725) | Nessus | Scientific Linux Local Security Checks | high |
111343 | Scientific Linux Security Update : thunderbird on SL6.x i386/x86_64 (20180725) | Nessus | Scientific Linux Local Security Checks | high |
111341 | CentOS 7 : thunderbird (CESA-2018:2252) | Nessus | CentOS Local Security Checks | high |
111323 | RHEL 7 : thunderbird (RHSA-2018:2252) | Nessus | Red Hat Local Security Checks | high |
111322 | RHEL 6 : thunderbird (RHSA-2018:2251) | Nessus | Red Hat Local Security Checks | high |
111320 | Oracle Linux 7 : thunderbird (ELSA-2018-2252) | Nessus | Oracle Linux Local Security Checks | high |
111319 | Oracle Linux 6 : thunderbird (ELSA-2018-2251) | Nessus | Oracle Linux Local Security Checks | high |
111087 | Debian DSA-4244-1 : thunderbird - security update | Nessus | Debian Local Security Checks | high |
111083 | Debian DLA-1425-1 : thunderbird security update | Nessus | Debian Local Security Checks | high |
111074 | CentOS 6 : firefox (CESA-2018:2112) | Nessus | CentOS Local Security Checks | high |
111060 | Ubuntu 14.04 LTS / 16.04 LTS / 17.10 / 18.04 LTS : Thunderbird vulnerabilities (USN-3714-1) | Nessus | Ubuntu Local Security Checks | high |
111044 | Mozilla Thunderbird < 52.9 Multiple Vulnerabilities | Nessus | Windows | high |
111043 | Mozilla Thunderbird < 52.9 Multiple Vulnerabilities (macOS) | Nessus | MacOS X Local Security Checks | high |
111013 | CentOS 7 : firefox (CESA-2018:2113) | Nessus | CentOS Local Security Checks | high |
111005 | Ubuntu 14.04 LTS / 16.04 LTS / 17.10 / 18.04 LTS : Firefox regressions (USN-3705-2) | Nessus | Ubuntu Local Security Checks | high |
110971 | Scientific Linux Security Update : firefox on SL6.x i386/x86_64 (20180628) | Nessus | Scientific Linux Local Security Checks | high |
110959 | openSUSE Security Update : Mozilla Thunderbird (openSUSE-2018-701) | Nessus | SuSE Local Security Checks | high |
110942 | Ubuntu 14.04 LTS / 16.04 LTS / 17.10 / 18.04 LTS : firefox vulnerabilities (USN-3705-1) | Nessus | Ubuntu Local Security Checks | high |
110935 | Scientific Linux Security Update : firefox on SL7.x x86_64 (20180628) | Nessus | Scientific Linux Local Security Checks | high |
110917 | Oracle Linux 7 : firefox (ELSA-2018-2113) | Nessus | Oracle Linux Local Security Checks | high |
110815 | Debian DLA-1406-1 : firefox-esr security update | Nessus | Debian Local Security Checks | high |
110811 | Mozilla Firefox < 61 Multiple Critical Vulnerabilities | Nessus | Windows | high |
110810 | Mozilla Firefox ESR < 60.1 Multiple Critical Vulnerabilities | Nessus | Windows | high |
110809 | Mozilla Firefox ESR < 52.9 Multiple Critical Vulnerabilities | Nessus | Windows | high |
110808 | Mozilla Firefox ESR < 60.1 Multiple Vulnerabilities (macOS) | Nessus | MacOS X Local Security Checks | high |
110807 | Mozilla Firefox ESR < 52.9 Multiple Vulnerabilities (macOS) | Nessus | MacOS X Local Security Checks | high |
110806 | Mozilla Firefox < 61 Multiple Critical Vulnerabilities (macOS) | Nessus | MacOS X Local Security Checks | high |
110801 | openSUSE Security Update : MozillaFirefox (openSUSE-2018-676) | Nessus | SuSE Local Security Checks | high |
110800 | RHEL 7 : firefox (RHSA-2018:2113) | Nessus | Red Hat Local Security Checks | high |
110799 | RHEL 6 : firefox (RHSA-2018:2112) | Nessus | Red Hat Local Security Checks | high |
110729 | Debian DSA-4235-1 : firefox-esr - security update | Nessus | Debian Local Security Checks | high |
110700 | FreeBSD : mozilla -- multiple vulnerabilities (cd81806c-26e7-4d4a-8425-02724a2f48af) | Nessus | FreeBSD Local Security Checks | high |