SB2018091102 - Security restrictions bypass in NoScript extension for Tor and Firefox ESR
Published: September 11, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security feature bypass (CVE-ID: N/A)
The vulnerability allows a remote attacker to bypass implemented security features.
The vulnerability exists due to an error when processing "Content-Type" header. A remote attacker can bypass restrictions imposed by the NoScript browser extension via "text/html;/json" value for the "Content-Type" header and execute arbitrary JavaScript code in browser. The vulnerable extension is used by Tor and Firefox ESR browsers.
Remediation
Install update from vendor's website.