CVE-2019-11717Improper Encoding or Escaping of Output in Mozilla Firefox

Severity
5.3MEDIUMNVD
EPSS
4.7%
top 10.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateMay 24

Description

A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages8 packages

CVEListV5mozilla/firefoxunspecified68
NVDmozilla/firefox< 60.8.0+1
CVEListV5mozilla/firefox_esrunspecified60.8
CVEListV5mozilla/thunderbirdunspecified60.8
NVDmozilla/thunderbird< 60.8.0

Also affects: Debian Linux 8.0

🔴Vulnerability Details

4
GHSA
GHSA-vp8c-39q7-pxqc: A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for2022-05-24
OSV
CVE-2019-11717: A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for2019-07-23
CVEList
CVE-2019-11717: A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for2019-07-23
OSV
thunderbird vulnerabilities2019-07-17

📋Vendor Advisories

4
Ubuntu
Thunderbird vulnerabilities2019-07-17
Ubuntu
Firefox vulnerabilities2019-07-12
Red Hat
Mozilla: Caret character improperly escaped in origins2019-07-10
Debian
CVE-2019-11717: firefox - A vulnerability exists where the caret ("^") character is improperly escaped con...2019

💬Community

1
Bugzilla
CVE-2019-11717 Mozilla: Caret character improperly escaped in origins2019-07-10
CVE-2019-11717 — Mozilla Firefox vulnerability | cvebase