Cleartext transmission of sensitive information in Mozilla Firefox - CVE-2019-17002

 

Cleartext transmission of sensitive information in Mozilla Firefox - CVE-2019-17002

Published: October 23, 2019


Vulnerability identifier: #VU22172
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-17002
CWE-ID: CWE-319
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to software processes  upgrade-insecure-requests in the Content Security Policy, and a link is dragged and dropped from such page. As a result, the link is not upgraded to https and allows to transmit data over unencrypted channel.


Affected software

Mozilla Firefox
Arch Linux
firefox (Ubuntu package)
firefox (Alpine package)

How to mitigate CVE-2019-17002

Install updates from vendor's website.

Mozilla Firefox - update to 70.0
firefox (Ubuntu package) - addressed in versions 70.0+build2-0ubuntu0.16.04.1, 70.0+build2-0ubuntu0.18.04.1, 70.0+build2-0ubuntu0.19.04.1, 70.0+build2-0ubuntu0.19.10.1

External References

Related Security Bulletins