CVE-2019-11748
Mozilla: Persistence of WebRTC permissions in a third party context
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. In light of recent high profile vulnerabilities in other software, a decision was made to no longer persist these permissions. This avoids the possibility of trusted WebRTC resources being invisibly embedded in web content and abusing permissions previously given by users. Users will now be prompted for permissions on each use. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
WebRTC en Firefox respetará los permisos persistentes otorgados a los sitios para acceder a recursos de micrófono y cámara incluso en un contexto de terceros. A la luz de las recientes vulnerabilidades de alto perfil en otro software, se tomó la decisión de no conservar estos permisos. Esto evita la posibilidad de que los recursos confiables de WebRTC se incorporen de forma no visible en el contenido web y abusen de los permisos otorgados previamente por los usuarios. Ahora se solicitará a los usuarios permisos para cada uso. Esta vulnerabilidad afecta a Firefox versiones anteriores a 69 y Firefox ESR versiones anteriores a 68.1.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-05-03 CVE Reserved
- 2019-09-04 CVE Published
- 2024-08-04 CVE Updated
- 2024-09-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-281: Improper Preservation of Permissions
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
References (6)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | < 69.0 Search vendor "Mozilla" for product "Firefox" and version " < 69.0" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Esr Search vendor "Mozilla" for product "Firefox Esr" | < 68.1.0 Search vendor "Mozilla" for product "Firefox Esr" and version " < 68.1.0" | - |
Affected
|