CVE-2019-11748Improper Preservation of Permissions in Mozilla Firefox

Severity
6.5MEDIUMNVD
OSV9.8
EPSS
0.3%
top 46.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 27
Latest updateMay 24

Description

WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. In light of recent high profile vulnerabilities in other software, a decision was made to no longer persist these permissions. This avoids the possibility of trusted WebRTC resources being invisibly embedded in web content and abusing permissions previously given by users. Users will now be prompted for permissions on each use. This vulnerability aff

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages7 packages

debiandebian/firefox< firefox 69.0-1 (sid)
CVEListV5mozilla/firefoxunspecified69
NVDmozilla/firefox< 69.0
debiandebian/firefox-esr< firefox 69.0-1 (sid)
CVEListV5mozilla/firefox_esrunspecified68.1

🔴Vulnerability Details

4
GHSA
GHSA-pf67-g7x9-r27m: WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context2022-05-24
OSV
firefox regression2019-10-08
OSV
CVE-2019-11748: WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context2019-09-27
OSV
firefox vulnerabilities2019-09-04

📋Vendor Advisories

4
Ubuntu
Firefox regression2019-10-08
Ubuntu
Firefox vulnerabilities2019-09-04
Red Hat
Mozilla: Persistence of WebRTC permissions in a third party context2019-09-03
Debian
CVE-2019-11748: firefox - WebRTC in Firefox will honor persisted permissions given to sites for access to ...2019

💬Community

2
Bugzilla
CVE-2019-11748 Mozilla: Persistence of WebRTC permissions in a third party context2019-09-04
Bugzilla
Firefox 69.0 is available2019-09-03