CVE-2019-11723Origin Validation Error in Mozilla Firefox

Severity
7.5HIGHNVD
OSV9.8
EPSS
0.3%
top 45.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateMay 24

Description

A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" for people who use the Firefox Multi-Account Containers Web Extension. This vulnerability affects Firefox < 68.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

debiandebian/firefox< firefox 68.0-1 (sid)
CVEListV5mozilla/firefoxunspecified68
NVDmozilla/firefox< 68.0
Ubuntumozilla/firefox< 68.0+build3-0ubuntu0.16.04.1+3
NVDopensuse/leap15.0, 15.1+1

🔴Vulnerability Details

4
GHSA
GHSA-2j5m-fjjv-cj2h: A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context2022-05-24
OSV
firefox regressions2019-07-25
OSV
firefox vulnerabilities2019-07-12
OSV
CVE-2019-11723: A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context2019-07-11

📋Vendor Advisories

4
Ubuntu
Firefox regressions2019-07-25
Ubuntu
Firefox vulnerabilities2019-07-12
Red Hat
Mozilla: Cookie leakage during add-on fetching across private browsing boundaries2019-07-09
Debian
CVE-2019-11723: firefox - A vulnerability exists during the installation of add-ons where the initial fetc...2019

💬Community

1
Bugzilla
CVE-2019-11723 Mozilla: Cookie leakage during add-on fetching across private browsing boundaries2019-07-18