CVE-2019-11724

CVSS v3.1 6.1 (Medium)
61% Progress
CVSS v2.0 5.8 (Medium)
58% Progress
EPSS 0.19 % (56th)
0.19% Progress
Affected Products 2
Advisories 13

Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to another site. This additional permission is unnecessary and is a potential vector for malicious attacks. This vulnerability affects Firefox < 68.

Weaknesses
CWE-863
Incorrect Authorization
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2019-07-23 14:15:16
(5 years ago)
Updated Date
2023-01-31 14:14:11
(19 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 68.0 version cpe:2.3:a:mozilla:firefox < 68.0

Configuration #2

    CPE23 From Up To
  Opensuse Leap 15.0 cpe:2.3:o:opensuse:leap:15.0
  Opensuse Leap 15.1 cpe:2.3:o:opensuse:leap:15.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...