CVE-2019-11723 Vulnerability Details

  /     /     /  

CVE-2019-11723 Metadata Quick Info

CVE Published: 23/07/2019 | CVE Updated: 04/08/2024 | CVE Year: 2019
Source: mozilla | Vendor: Mozilla | Product: Firefox
Status : PUBLISHED

CVE-2019-11723 Description

A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" for people who use the Firefox Multi-Account Containers Web Extension. This vulnerability affects Firefox < 68.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Cookie leakage during add-on fetching across private browsing boundaries
Source: Mozilla

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description: