CVE-2019-11761

Name
CVE-2019-11761
Description
By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Vendor Advisory https://www.mozilla.org/security/advisories/mfsa2019-35/
Permissions Required https://bugzilla.mozilla.org/show_bug.cgi?id=1561502
Vendor Advisory https://www.mozilla.org/security/advisories/mfsa2019-34/
Vendor Advisory https://www.mozilla.org/security/advisories/mfsa2019-33/
GENTOO https://security.gentoo.org/glsa/202003-10
UBUNTU https://usn.ubuntu.com/4335-1/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* firefox >= None < 70.0
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* firefox_esr >= None < 68.2
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* thunderbird >= None < 68.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status