firefox: stored passwords in 'Saved Logins' can be copied without master password entry
Published Sep 27, 2019
9.8
CRITICALCVSS 3.1
EPSS 1.41%
Description
When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It was found that locally stored passwords can be copied to the clipboard thorough the 'copy password' context menu item without re-entering the master password if the master password had been previously entered in the same session, allowing for potential theft of stored passwords. This vulnerability affects Firefox < 68.0.2 and Firefox ESR < 68.0.2.
Affected products
-
Affected
- ≥ unspecified, < 68.0.2
-
Affected
- ≥ unspecified, < 68.0.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Mozilla | Firefox | unknown | Affected
|
| Mozilla | Firefox ESR | unknown | Affected
|
No data.
Red Hat Enterprise Linux 6
firefox-0:60.9.0-1.el6_10
Fixed · RHSA-2019:2694
Red Hat Enterprise Linux 7
firefox-0:60.9.0-1.el7_7
Fixed · RHSA-2019:2729
Red Hat Enterprise Linux 8
firefox-0:68.1.0-1.el8_0
Fixed · RHSA-2019:2663
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | firefox-0:60.9.0-1.el6_10 | Fixed | RHSA-2019:2694 |
| Red Hat Enterprise Linux 7 | firefox-0:60.9.0-1.el7_7 | Fixed | RHSA-2019:2729 |
| Red Hat Enterprise Linux 8 | firefox-0:68.1.0-1.el8_0 | Fixed | RHSA-2019:2663 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00011.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00017.html vendor-advisoryx_refsource_SUSE
- https://access.redhat.com/security/cve/CVE-2019-11733 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1565780 x_refsource_MISCIssue TrackingPermissions RequiredVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1745687 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-3403 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-11733
- https://www.cve.org/CVERecord?id=CVE-2019-11733
- https://www.mozilla.org/en-US/security/advisories/mfsa2019-24/
- https://www.mozilla.org/security/advisories/mfsa2019-24/ x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00011.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00017.html | vendor-advisoryx_refsource_SUSE | |
| https://access.redhat.com/security/cve/CVE-2019-11733 | Vendor Advisory | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1565780 | x_refsource_MISCIssue TrackingPermissions RequiredVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1745687 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-3403 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-11733 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-11733 | ||
| https://www.mozilla.org/en-US/security/advisories/mfsa2019-24/ | ||
| https://www.mozilla.org/security/advisories/mfsa2019-24/ | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data