By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
References
Link | Resource |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1561502 | Issue Tracking Permissions Required |
https://security.gentoo.org/glsa/202003-10 | Third Party Advisory |
https://usn.ubuntu.com/4335-1/ | Third Party Advisory |
https://www.mozilla.org/security/advisories/mfsa2019-33/ | Vendor Advisory |
https://www.mozilla.org/security/advisories/mfsa2019-34/ | Vendor Advisory |
https://www.mozilla.org/security/advisories/mfsa2019-35/ | Vendor Advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=1561502 | Issue Tracking Permissions Required |
https://security.gentoo.org/glsa/202003-10 | Third Party Advisory |
https://usn.ubuntu.com/4335-1/ | Third Party Advisory |
https://www.mozilla.org/security/advisories/mfsa2019-33/ | Vendor Advisory |
https://www.mozilla.org/security/advisories/mfsa2019-34/ | Vendor Advisory |
https://www.mozilla.org/security/advisories/mfsa2019-35/ | Vendor Advisory |
Configurations
History
21 Nov 2024, 04:21
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=1561502 - Issue Tracking, Permissions Required | |
References | () https://security.gentoo.org/glsa/202003-10 - Third Party Advisory | |
References | () https://usn.ubuntu.com/4335-1/ - Third Party Advisory | |
References | () https://www.mozilla.org/security/advisories/mfsa2019-33/ - Vendor Advisory | |
References | () https://www.mozilla.org/security/advisories/mfsa2019-34/ - Vendor Advisory | |
References | () https://www.mozilla.org/security/advisories/mfsa2019-35/ - Vendor Advisory |
Information
Published : 2020-01-08 20:15
Updated : 2024-11-21 04:21
NVD link : CVE-2019-11761
Mitre link : CVE-2019-11761
CVE.ORG link : CVE-2019-11761
JSON object : View
Products Affected
canonical
- ubuntu_linux
mozilla
- thunderbird
- firefox
- firefox_esr