CVE-2019-11761
Summary
| CVE | CVE-2019-11761 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-08 20:15:00 UTC |
| Updated | 2023-02-01 14:08:00 UTC |
| Description | By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2. |
Risk And Classification
Problem Types: CWE-362 | CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Firefox Esr | All | All | All | All |
| Application | Mozilla | Firefox Esr | All | All | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Mozilla Thunderbird: Multiple vulnerabilities (GLSA 202003-10) — Gentoo security | GENTOO | security.gentoo.org | |
| Security vulnerabilities fixed in - Thunderbird 68.2 — Mozilla | CONFIRM | www.mozilla.org | Vendor Advisory |
| 1561502 - (CVE-2019-11761) By using a form with a data URI it's possible to gain access to the privileged JSONView object that has been cloned into content. | CONFIRM | bugzilla.mozilla.org | Permissions Required |
| USN-4335-1: Thunderbird vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| Security vulnerabilities fixed in - Firefox ESR 68.2 — Mozilla | CONFIRM | www.mozilla.org | Vendor Advisory |
| Security vulnerabilities fixed in - Firefox 70 — Mozilla | CONFIRM | www.mozilla.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.