CVE-2019-11762: Medium severity Mozilla Firefox vulnerability
A flaw was found in Mozilla's firefox and thunderbird where if two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This could cause an interaction between two different sites on two different windows running under the same application.
Other sources
If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-33/#CVE-2019-11762
— Red Hat
If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-11762?
CVE-2019-11762 is a vulnerability in Mozilla's Firefox and Thunderbird that allows two same-origin documents to call arbitrary DOM methods/getters/setters on a cross-origin window.
What is the severity of CVE-2019-11762?
CVE-2019-11762 has a severity rating of medium with a CVSS score of 6.1.
Which software is affected by CVE-2019-11762?
Firefox versions 68.2.0-4.el6_10, 68.2.0-1.el7_7, 68.2.0-2.el8_0, and Thunderbird versions 68.2.0-2.el6_10, 68.2.0-1.el7_7, 68.2.0-1.el8_0 are affected by CVE-2019-11762.
How can CVE-2019-11762 be remediated?
To remediate CVE-2019-11762, users should update their Firefox or Thunderbird software to versions 68.2.0 or later.
Where can I find more information about CVE-2019-11762?
Additional information about CVE-2019-11762 can be found in the following references: Mozilla Bugzilla - https://bugzilla.mozilla.org/show_bug.cgi?id=1582857, Mozilla MFSA2019-33 - https://www.mozilla.org/en-US/security/advisories/mfsa2019-33/, Mozilla MFSA2019-35 - https://www.mozilla.org/en-US/security/advisories/mfsa2019-35/