PT-2019-4864 · Mozilla+5 · Firefox+5

Michał Bentkowski

·

Published

2019-12-03

·

Updated

2024-12-12

·

CVE-2019-17016

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firefox ESR versions prior to 68.4 Firefox versions prior to 72
Description The issue arises when pasting a <style> tag from the clipboard into a rich text editor, causing the CSS sanitizer to incorrectly rewrite a @namespace rule. This could lead to injection into certain types of websites, resulting in data exfiltration. The vulnerability may allow a remote attacker to impact data integrity.
Recommendations For Firefox ESR versions prior to 68.4, update to version 68.4 or later. For Firefox versions prior to 72, update to version 72 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1013
ALT-PU-2020-1032
ALT-PU-2020-1110
ALT-PU-2020-1166
ALT-PU-2020-1515
ALT-PU-2020-1617
ALT-PU-2020-2408
ALT-PU-2020-2933
ALT-PU-2021-1368
BDU:2020-01450
CESA-2020_0085
CESA-2020_0086
CESA-2020_0111
CESA-2020_0120
CESA-2020_0123
CESA-2020_0127
CVE-2019-17016
DLA-2061-1
DLA-2071-1
DSA-4600-1
DSA-4603-1
MGASA-2020-0027
MGASA-2020-0034
OPENSUSE-SU-2020:0060-1
OPENSUSE-SU-2020:0094-1
OPENSUSE-SU-2020_0060-1
OPENSUSE-SU-2020_0094-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:10601-1
OPENSUSE-SU-2024:14572-1
RHSA-2020:0085
RHSA-2020:0086
RHSA-2020:0111
RHSA-2020:0120
RHSA-2020:0123
RHSA-2020:0127
RHSA-2020:0292
RHSA-2020:0295
RHSA-2020_0085
RHSA-2020_0086
RHSA-2020_0111
RHSA-2020_0120
RHSA-2020_0123
RHSA-2020_0127
SUSE-SU-2020:0068-1
SUSE-SU-2020:0078-1
SUSE-SU-2020:0142-1
SUSE-SU-2020:14268-1
USN-4234-1
USN-4234-2
USN-4241-1
USN-4335-1

Affected Products

Alt Linux
Centos
Firefox
Red Hat
Suse
Ubuntu