CVE-2019-11712

Advisory lineage Upstream: 0 Downstream: 36
Modified
Published: 23 Jul 2019, 13:19
Last modified:04 Aug 2024, 23:03

Vulnerability Summary

Overall Risk (default)
medium
35/100
CVSS Score
8.8 HIGH
v3.0 (nvd)
EPSS Score
0.29% LOW
0% probability -0.09%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Jul 2019, 13:19
Published
Vulnerability first disclosed
04 Aug 2024, 23:03
Last Modified
Vulnerability information updated

Description

POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS Metrics

  • v3.0HIGHScore: 8.8CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 0.29% Percentile: 52%

Techniques & Countermeasures

  • CWE-352Cross-Site Request Forgery (CSRF)

    The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Affected Systems

  • mozillafirefox

    < 60.8.0 | < 68.0 | ≥ unspecified, < 68

  • mozillafirefox_esr

    ≥ unspecified, < 60.8

  • mozillathunderbird

    < 60.8.0 | ≥ unspecified, < 60.8

References (13)