CVE-2019-11712: CSRF
POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-11712?
CVE-2019-11712 is a vulnerability that allows POST requests made by NPAPI plugins to bypass CORS requirements, leading to potential Cross-Site Request Forgery (CSRF) attacks.
Which software is affected by CVE-2019-11712?
CVE-2019-11712 affects Firefox ESR versions prior to 60.8, Firefox versions prior to 68, and Thunderbird versions prior to 60.8.
How severe is CVE-2019-11712?
CVE-2019-11712 is classified as a high severity vulnerability with a CVSS score of 8.8.
How can an attacker exploit CVE-2019-11712?
An attacker can exploit CVE-2019-11712 by tricking a user into visiting a malicious website that contains a CSRF attack, potentially leading to unauthorized actions on the user's behalf.
Is there a fix for CVE-2019-11712?
Yes, updating to Firefox ESR 60.8, Firefox 68, or Thunderbird 60.8 or later versions will resolve the vulnerability.