CVE-2019-11717

Advisory lineage Upstream: 0 Downstream: 36
Modified
Published: 23 Jul 2019, 13:18
Last modified:04 Aug 2024, 23:03

Vulnerability Summary

Overall Risk (default)
medium
32/100
CVSS Score
5.3 MEDIUM
v3.1 (nvd)
EPSS Score
3.19% LOW
3% probability -1.82%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

23 Jul 2019, 13:18
Published
Vulnerability first disclosed
04 Aug 2024, 23:03
Last Modified
Vulnerability information updated

Description

A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS Metrics

  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 3.19% Percentile: 87%

Techniques & Countermeasures

  • CWE-116Improper Encoding or Escaping of Output

    The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Affected Systems

  • debiandebian_linux

    8.0

  • mozillafirefox

    < 60.8.0 | < 68.0 | ≥ unspecified, < 68

  • mozillafirefox_esr

    ≥ unspecified, < 60.8

  • mozillathunderbird

    < 60.8.0 | ≥ unspecified, < 60.8

  • novellsuse_package_hub_for_suse_linux_enterprise

    12

  • opensuseleap

    15.0 | 15.1

References (13)