CVE-2019-11761

By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*

History

01 Feb 2023, 14:08

Type Values Removed Values Added
References (UBUNTU) https://usn.ubuntu.com/4335-1/ - (UBUNTU) https://usn.ubuntu.com/4335-1/ - Third Party Advisory
References (GENTOO) https://security.gentoo.org/glsa/202003-10 - (GENTOO) https://security.gentoo.org/glsa/202003-10 - Third Party Advisory
References (CONFIRM) https://bugzilla.mozilla.org/show_bug.cgi?id=1561502 - Permissions Required (CONFIRM) https://bugzilla.mozilla.org/show_bug.cgi?id=1561502 - Issue Tracking, Permissions Required
First Time Canonical
Canonical ubuntu Linux
CPE cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*

Information

Published : 2020-01-08 20:15

Updated : 2023-12-10 13:13


NVD link : CVE-2019-11761

Mitre link : CVE-2019-11761

CVE.ORG link : CVE-2019-11761


JSON object : View

Products Affected

mozilla

  • thunderbird
  • firefox
  • firefox_esr

canonical

  • ubuntu_linux
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CWE-862

Missing Authorization