CVE-2019-11723 — Origin Validation Error in Mozilla Firefox
Severity
7.5HIGHNVD
OSV9.8
EPSS
0.3%
top 45.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 23
Latest updateMay 24
Description
A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" for people who use the Firefox Multi-Account Containers Web Extension. This vulnerability affects Firefox < 68.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages5 packages
🔴Vulnerability Details
4GHSA▶
GHSA-2j5m-fjjv-cj2h: A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context↗2022-05-24
OSV▶
CVE-2019-11723: A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context↗2019-07-11
📋Vendor Advisories
4💬Community
1Bugzilla▶
CVE-2019-11723 Mozilla: Cookie leakage during add-on fetching across private browsing boundaries↗2019-07-18