CVE-2019-13075 Information
Feb 14, 2021
cve
Description
Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser’s language via vectors involving an IFRAME element because text in that language is included in the title attribute of a LINK element for a non-HTML page. This is related to a behavior of Firefox before 68.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
https://hackerone.com/reports/588239 https://trac.torproject.org/projects/tor/ticket/30657
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: