← Volver a CVEs
CVE-2019-11711
HIGH8.8
Descripcion
When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Detalles CVE
Puntuacion CVSS v3.18.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioREQUIRED
Publicado7/23/2019
Ultima modificacion11/25/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
debian:debian_linuxmozilla:firefoxmozilla:thunderbird
Referencias
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.html(security@mozilla.org)
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00058.html(security@mozilla.org)
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00073.html(security@mozilla.org)
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00009.html(security@mozilla.org)
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00010.html(security@mozilla.org)
https://bugzilla.mozilla.org/show_bug.cgi?id=1552541(security@mozilla.org)
https://lists.debian.org/debian-lts-announce/2019/08/msg00001.html(security@mozilla.org)
https://lists.debian.org/debian-lts-announce/2019/08/msg00002.html(security@mozilla.org)
https://security.gentoo.org/glsa/201908-12(security@mozilla.org)
https://security.gentoo.org/glsa/201908-20(security@mozilla.org)
https://www.mozilla.org/security/advisories/mfsa2019-21/(security@mozilla.org)
https://www.mozilla.org/security/advisories/mfsa2019-22/(security@mozilla.org)
https://www.mozilla.org/security/advisories/mfsa2019-23/(security@mozilla.org)
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.html(af854a3a-2127-422b-91ae-364da2661108)
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00058.html(af854a3a-2127-422b-91ae-364da2661108)
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00073.html(af854a3a-2127-422b-91ae-364da2661108)
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00009.html(af854a3a-2127-422b-91ae-364da2661108)
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00010.html(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.mozilla.org/show_bug.cgi?id=1552541(af854a3a-2127-422b-91ae-364da2661108)
https://lists.debian.org/debian-lts-announce/2019/08/msg00001.html(af854a3a-2127-422b-91ae-364da2661108)
https://lists.debian.org/debian-lts-announce/2019/08/msg00002.html(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/201908-12(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/201908-20(af854a3a-2127-422b-91ae-364da2661108)
https://www.mozilla.org/security/advisories/mfsa2019-21/(af854a3a-2127-422b-91ae-364da2661108)
https://www.mozilla.org/security/advisories/mfsa2019-22/(af854a3a-2127-422b-91ae-364da2661108)
https://www.mozilla.org/security/advisories/mfsa2019-23/(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.