PT-2018-3985 · Mozilla+3 · Firefox+3
Andrey
·
Published
2018-08-15
·
Updated
2024-12-12
·
CVE-2019-11725
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 68
Description
The issue is related to shortcomings in the authorization procedure of the Firefox web browser. It may allow a remote attacker to compromise data integrity. When a user visits a site marked as unsafe by the Safebrowsing API, warning messages are displayed, but resources from the same site loaded through websockets are not blocked, leading to the loading of unsafe resources and bypassing safebrowsing protections.
Recommendations
For Firefox versions prior to 68, update to version 68 or later to resolve the issue. As a temporary workaround, consider restricting the use of websockets for sites marked as unsafe by the Safebrowsing API until a patch is available. Avoid using websockets to load resources from potentially unsafe sites until the issue is resolved.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Firefox
Suse
Ubuntu