[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2019-11761Date: (C)2019-10-23   (M)2024-04-17


By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 5.4CVSS Score :
Exploit Score: 2.8Exploit Score:
Impact Score: 2.5Impact Score:
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector:
Attack Complexity: LOWAccess Complexity:
Privileges Required: NONEAuthentication:
User Interaction: REQUIREDConfidentiality:
Scope: UNCHANGEDIntegrity:
Confidentiality: LOWAvailability:
Integrity: LOW 
Availability: NONE 
  
Reference:
GLSA-202003-10
USN-4335-1
https://bugzilla.mozilla.org/show_bug.cgi?id=1561502
https://www.mozilla.org/en-US/security/advisories/mfsa2019-34/
https://www.mozilla.org/security/advisories/mfsa2019-33/
https://www.mozilla.org/security/advisories/mfsa2019-34/
https://www.mozilla.org/security/advisories/mfsa2019-35/

CPE    2
cpe:/a:mozilla:firefox_esr
cpe:/a:mozilla:firefox
OVAL    42
oval:org.secpod.oval:def:604617
oval:org.secpod.oval:def:69769
oval:org.secpod.oval:def:2105077
oval:org.secpod.oval:def:66458
...

© SecPod Technologies