CVE-2019-11723
Summary
| CVE | CVE-2019-11723 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-23 14:15:00 UTC |
| Updated | 2023-01-31 14:14:00 UTC |
| Description | A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" for people who use the Firefox Multi-Account Containers Web Extension. This vulnerability affects Firefox < 68. |
Risk And Classification
Problem Types: CWE-346
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security vulnerabilities fixed in Firefox 68 — Mozilla | MISC | www.mozilla.org | Vendor Advisory |
| Mozilla Firefox: Multiple vulnerabilities (GLSA 201908-12) — Gentoo security | GENTOO | security.gentoo.org | |
| Access Denied | MISC | bugzilla.mozilla.org | Issue Tracking, Permissions Required, Vendor Advisory |
| [security-announce] openSUSE-SU-2019:2251-1: important: Security update | SUSE | lists.opensuse.org | |
| [security-announce] openSUSE-SU-2019:2249-1: important: Security update | SUSE | lists.opensuse.org | |
| [security-announce] openSUSE-SU-2019:2260-1: important: Security update | SUSE | lists.opensuse.org | |
| [security-announce] openSUSE-SU-2019:2248-1: important: Security update | SUSE | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710148 Gentoo Linux Mozilla Firefox Multiple vulnerabilities (GLSA 201908-12)