CVE-2019-11711
published 2019-07-23CVE-2019-11711: When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever…
PriorityP340high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.63%
73.4th percentile
When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | firefox | < firefox 68.0-1 (sid) | firefox 68.0-1 (sid) |
| debian | firefox-esr | < firefox 68.0-1 (sid) | firefox 68.0-1 (sid) |
| debian | thunderbird | < firefox 68.0-1 (sid) | firefox 68.0-1 (sid) |
| mozilla | firefox | < 60.8.0 | 60.8.0 |
| mozilla | firefox | < 68.0 | 68.0 |
| mozilla | firefox | >= 0 < 68.0+build3-0ubuntu0.16.04.1 | 68.0+build3-0ubuntu0.16.04.1 |
| mozilla | firefox | >= 0 < 68.0.1+build1-0ubuntu0.16.04.1 | 68.0.1+build1-0ubuntu0.16.04.1 |
| mozilla | firefox | >= 0 < 68.0+build3-0ubuntu0.18.04.1 | 68.0+build3-0ubuntu0.18.04.1 |
| mozilla | firefox | >= 0 < 68.0.1+build1-0ubuntu0.18.04.1 | 68.0.1+build1-0ubuntu0.18.04.1 |
| mozilla | firefox | >= unspecified < 68 | 68 |
| mozilla | firefox_esr | >= unspecified < 60.8 | 60.8 |
| mozilla | thunderbird | < 60.8.0 | 60.8.0 |
| mozilla | thunderbird | >= 0 < 1:60.8.0-1 | 1:60.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.8.0-1 | 1:60.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.8.0-1 | 1:60.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.8.0-1 | 1:60.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.8.0+build1-0ubuntu0.16.04.2 | 1:60.8.0+build1-0ubuntu0.16.04.2 |
| mozilla | thunderbird | >= 0 < 1:60.8.0+build1-0ubuntu0.18.04.1 | 1:60.8.0+build1-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= unspecified < 60.8 | 60.8 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3cqf-mfjf-xv44: When an inner window is reused, it does not consider the use of document
ghsa_unreviewed·2022-05-24
CVE-2019-11711 [HIGH] GHSA-3cqf-mfjf-xv44: When an inner window is reused, it does not consider the use of document
When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
OSV
firefox regressions
osv·2019-07-25·CVSS 9.8
CVE-2019-9811 [CRITICAL] firefox regressions
firefox regressions
USN-4054-1 fixed vulnerabilities in Firefox. The update introduced
various minor regressions. This update fixes the problems.
We apologize for the inconvenience.
Original advisory details:
A sandbox escape was discovered in Firefox. If a user were tricked in to
installing a malicious language pack, an attacker could exploit this to
gain additional privileges. (CVE-2019-9811)
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information, bypass same origin restrictions, conduct cross-site scripting
(XSS) attacks, conduct cross-site request forgery (CSRF) attacks, spoof
origin attributes, spoof the addressbar
OSV
CVE-2019-11711: When an inner window is reused, it does not consider the use of document
osv·2019-07-23·CVSS 8.8
CVE-2019-11711 [HIGH] CVE-2019-11711: When an inner window is reused, it does not consider the use of document
When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
OSV
thunderbird vulnerabilities
osv·2019-07-17·CVSS 9.8
CVE-2019-9811 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
A sandbox escape was discovered in Thunderbird. If a user were tricked in to
installing a malicious language pack, an attacker could exploit this to
gain additional privileges. (CVE-2019-9811)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
bypass same origin restrictions, conduct cross-site scripting (XSS)
attacks, spoof origin attributes, or execute arbitrary code.
(CVE-2019-11709, CVE-2019-11711, CVE-2019-11712, CVE-2019-11713,
CVE-2019-11715, CVE-2019-11717)
It was discovered that NSS incorrectly handled importing certain
curve25519 private keys. An attacker could exploit this issue to c
OSV
firefox vulnerabilities
osv·2019-07-12·CVSS 9.8
CVE-2019-9811 [CRITICAL] firefox vulnerabilities
firefox vulnerabilities
A sandbox escape was discovered in Firefox. If a user were tricked in to
installing a malicious language pack, an attacker could exploit this to
gain additional privileges. (CVE-2019-9811)
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information, bypass same origin restrictions, conduct cross-site scripting
(XSS) attacks, conduct cross-site request forgery (CSRF) attacks, spoof
origin attributes, spoof the addressbar contents, bypass safebrowsing
protections, or execute arbitrary code. (CVE-2019-11709, CVE-2019-11710,
CVE-2019-11711, CVE-2019-11712, CVE-2019-11713, CVE-2019-11714,
CVE-2019-11715, CVE-2
Ubuntu
Firefox regressions
vendor_ubuntu·2019-07-25·CVSS 9.8
CVE-2019-9811 [CRITICAL] Firefox regressions
Title: Firefox regressions
Summary: USN-4054-1 caused some minor regressions in Firefox.
USN-4054-1 fixed vulnerabilities in Firefox. The update introduced
various minor regressions. This update fixes the problems.
We apologize for the inconvenience.
Original advisory details:
A sandbox escape was discovered in Firefox. If a user were tricked in to
installing a malicious language pack, an attacker could exploit this to
gain additional privileges. (CVE-2019-9811)
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information, bypass same origin restrictions, conduct cross-site scripting
(XSS) attacks, conduct cross-site request
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2019-07-17·CVSS 9.8
CVE-2019-9811 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
A sandbox escape was discovered in Thunderbird. If a user were tricked in to
installing a malicious language pack, an attacker could exploit this to
gain additional privileges. (CVE-2019-9811)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
bypass same origin restrictions, conduct cross-site scripting (XSS)
attacks, spoof origin attributes, or execute arbitrary code.
(CVE-2019-11709, CVE-2019-11711, CVE-2019-11712, CVE-2019-11713,
CVE-2019-11715, CVE-2019-11717)
It was discovered that NSS incorrectly handled importing certai
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2019-07-12·CVSS 9.8
CVE-2019-9811 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
A sandbox escape was discovered in Firefox. If a user were tricked in to
installing a malicious language pack, an attacker could exploit this to
gain additional privileges. (CVE-2019-9811)
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information, bypass same origin restrictions, conduct cross-site scripting
(XSS) attacks, conduct cross-site request forgery (CSRF) attacks, spoof
origin attributes, spoof the addressbar contents, bypass safebrowsing
protections, or execute arbitrary code. (CVE-2
Red Hat
Mozilla: Script injection within domain through inner window reuse
vendor_redhat·2019-07-10·CVSS 8.8
CVE-2019-11711 [HIGH] CWE-212 Mozilla: Script injection within domain through inner window reuse
Mozilla: Script injection within domain through inner window reuse
When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Package: firefox (Red Hat Enterprise Linux 5) - Out of support scope
Debian
CVE-2019-11711: firefox - When an inner window is reused, it does not consider the use of document.domain ...
vendor_debian·2019·CVSS 8.8
CVE-2019-11711 [HIGH] CVE-2019-11711: firefox - When an inner window is reused, it does not consider the use of document.domain ...
When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Scope: local
sid: resolved (fixed in 68.0-1)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-07/msg00058.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00073.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00010.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1552541https://lists.debian.org/debian-lts-announce/2019/08/msg00001.htmlhttps://lists.debian.org/debian-lts-announce/2019/08/msg00002.htmlhttps://security.gentoo.org/glsa/201908-12https://security.gentoo.org/glsa/201908-20https://www.mozilla.org/security/advisories/mfsa2019-21/https://www.mozilla.org/security/advisories/mfsa2019-22/https://www.mozilla.org/security/advisories/mfsa2019-23/http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-07/msg00058.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00073.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00010.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1552541https://lists.debian.org/debian-lts-announce/2019/08/msg00001.htmlhttps://lists.debian.org/debian-lts-announce/2019/08/msg00002.htmlhttps://security.gentoo.org/glsa/201908-12https://security.gentoo.org/glsa/201908-20https://www.mozilla.org/security/advisories/mfsa2019-21/https://www.mozilla.org/security/advisories/mfsa2019-22/https://www.mozilla.org/security/advisories/mfsa2019-23/
2019-07-23
Published