Related Vulnerabilities: CVE-2017-7831  

A vulnerability has been found in Firefox before 57.0 where the security wrapper does not deny access to some exposed properties using the deprecated exposedProps mechanism on proxy objects. These properties should be explicitly unavailable to proxy objects.

Severity Medium

Remote Yes

Type Information disclosure

Description

A vulnerability has been found in Firefox before 57.0  where the security wrapper does not deny access to some exposed properties using the deprecated exposedProps mechanism on proxy objects. These properties should be explicitly unavailable to proxy objects.

AVG-494 firefox 56.0.2-1 57.0-1 Critical Fixed

15 Nov 2017 ASA-201711-23 AVG-494 firefox Critical multiple issues

https://www.mozilla.org/en-US/security/advisories/mfsa2017-24/#CVE-2017-7831
https://bugzilla.mozilla.org/show_bug.cgi?id=1392026