CVE-2019-11733
Summary
| CVE | CVE-2019-11733 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-27 18:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It was found that locally stored passwords can be copied to the clipboard thorough the 'copy password' context menu item without re-entering the master password if the master password had been previously entered in the same session, allowing for potential theft of stored passwords. This vulnerability affects Firefox < 68.0.2 and Firefox ESR < 68.0.2. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [security-announce] openSUSE-SU-2019:2251-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| 1565780 - (CVE-2019-11733) Ability to copy password from password manager without entering master password |
MISC |
bugzilla.mozilla.org |
Issue Tracking, Permissions Required, Vendor Advisory |
| [security-announce] openSUSE-SU-2019:2260-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| Stored passwords in 'Saved Logins' can be copied without master password entry — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500920 Alpine Linux Security Update for firefox-esr
- 500943 Alpine Linux Security Update for firefox
- 503828 Alpine Linux Security Update for firefox
- 504785 Alpine Linux Security Update for firefox-esr