CVE-2019-11747Improper Initialization in Mozilla Firefox

Severity
6.5MEDIUMNVD
OSV9.8
EPSS
0.4%
top 42.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 27
Latest updateMay 24

Description

The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site. This includes removing any HTTP Strict Transport Security (HSTS) settings received from sites that use it. Due to a bug, sites on the pre-load list also have their HSTS setting removed. On the next visit to that site if the user specifies an http: URL rather than secure https: they will not be protected by the pre-loaded HSTS setting. After that visit the s

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages7 packages

debiandebian/firefox< firefox 69.0-1 (sid)
CVEListV5mozilla/firefoxunspecified69
NVDmozilla/firefox< 69.0
debiandebian/firefox-esr< firefox 69.0-1 (sid)
CVEListV5mozilla/firefox_esrunspecified68.1

🔴Vulnerability Details

4
GHSA
GHSA-9f7j-g98g-532j: The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site2022-05-24
OSV
firefox regression2019-10-08
OSV
CVE-2019-11747: The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site2019-09-27
OSV
firefox vulnerabilities2019-09-04

📋Vendor Advisories

4
Ubuntu
Firefox regression2019-10-08
Ubuntu
Firefox vulnerabilities2019-09-04
Red Hat
Mozilla: 'Forget about this site' removes sites from pre-loaded HSTS list2019-09-03
Debian
CVE-2019-11747: firefox - The "Forget about this site" feature in the History pane is intended to remove a...2019

💬Community

2
Bugzilla
CVE-2019-11747 Mozilla: 'Forget about this site' removes sites from pre-loaded HSTS list2019-09-04
Bugzilla
Firefox 69.0 is available2019-09-03