CVE-2019-11761: Race Condition
A vulnerability was found in Mozilla Firefox and Thunderbird. Privileged JSONView objects that have been cloned into content can be accessed using a form with a data URI. This flaw bypasses existing defense-in-depth mechanisms and can be exploited over the network.
Other sources
By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-33/#CVE-2019-11761
— Red Hat
By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-11761?
CVE-2019-11761 is a vulnerability that allows an attacker to gain access to the privileged JSONView object in Firefox and Thunderbird.
How does CVE-2019-11761 impact systems?
Exposing the privileged JSONView object could bypass existing defense mechanisms, although the impact appears to be minimal.
Which software versions are affected by CVE-2019-11761?
Firefox versions prior to 70 and Thunderbird versions prior to 68.2 are affected by CVE-2019-11761.
What is the severity of CVE-2019-11761?
CVE-2019-11761 has a severity rating of medium, with a CVSS score of 5.4.
How do I fix CVE-2019-11761?
To fix CVE-2019-11761, users should update their Firefox and Thunderbird installations to versions 70 and 68.2, respectively.