CVE-2019-11733

CVSS v3.1 9.8 (Critical)
98% Progress
CVSS v2.0 5 (Medium)
50% Progress
EPSS 0.28 % (69th)
0.28% Progress
Affected Products 2
Advisories 14

When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It was found that locally stored passwords can be copied to the clipboard thorough the 'copy password' context menu item without re-entering the master password if the master password had been previously entered in the same session, allowing for potential theft of stored passwords. This vulnerability affects Firefox < 68.0.2 and Firefox ESR < 68.0.2.

Weaknesses
CWE-287
Improper Authentication
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2019-09-27 18:15:11
(5 years ago)
Updated Date
2020-08-24 17:37:01
(4 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 68.0.2 version cpe:2.3:a:mozilla:firefox < 68.0.2
  Mozilla Firefox Esr prior 68.0.2 version cpe:2.3:a:mozilla:firefox_esr < 68.0.2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...