CVE-2019-9808 Information

Description

If WebRTC permission is requested from documents with data: or blob: URLs the permission notifications do not properly display the originating domain. The notification states \Unknown origin\ as the requestee leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox 66.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Reference

https://bugzilla.mozilla.org/show_bug.cgi?id=1434634 https://www.mozilla.org/security/advisories/mfsa2019-07/

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

LOW

Base Score

NONE

Base Severity

5.3

Share on: