PT-2019-5152 · Mozilla+5 · Firefox+5

Wladimir Palant

·

Published

2019-09-03

·

Updated

2024-12-12

·

CVE-2019-11738

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 69 Firefox ESR versions prior to 68.1
Description The issue is related to Content Security Policy (CSP) directives that use hash-based sources. If such a directive is defined with an empty string as input, it allows the execution of any javascript: URIs, potentially bypassing CSP permissions and enabling malicious JavaScript content to run. This could allow a remote attacker to execute arbitrary code.
Recommendations For Firefox versions prior to 69, update to version 69 or later to resolve the issue. For Firefox ESR versions prior to 68.1, update to version 68.1 or later to resolve the issue.

Exploit

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2640
ALT-PU-2019-2644
ALT-PU-2019-2686
ALT-PU-2020-1617
ALT-PU-2020-2408
ALT-PU-2020-2933
ALT-PU-2021-1368
BDU:2020-01822
CESA-2019_2663
CVE-2019-11738
MGASA-2019-0268
OPENSUSE-SU-2019:2251-1
OPENSUSE-SU-2019:2260-1
OPENSUSE-SU-2019_2251-1
OPENSUSE-SU-2019_2260-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
RHSA-2019:2663
RHSA-2019_2663
SUSE-SU-2019:14246-1
SUSE-SU-2019:2545-1
SUSE-SU-2019:2620-1
SUSE-SU-2019_14246-1
USN-4122-1
USN-4122-2

Affected Products

Alt Linux
Centos
Firefox
Red Hat
Suse
Ubuntu