CVE-2019-11733

CRITICAL

Firefox < 68.0.2 - Unauthenticated Password Theft via Clipboard Copy

Title source: llm
STIX 2.1

Description

When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It was found that locally stored passwords can be copied to the clipboard thorough the 'copy password' context menu item without re-entering the master password if the master password had been previously entered in the same session, allowing for potential theft of stored passwords. This vulnerability affects Firefox < 68.0.2 and Firefox ESR < 68.0.2.

References (4)

Core 4
Core References
Issue Tracking, Permissions Required, Vendor Advisory x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=1565780
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2019-24/

Scores

CVSS v3 9.8
EPSS 0.0039
EPSS Percentile 60.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
mozilla/firefox < 68.0.2
Published Sep 27, 2019
Tracked Since Feb 18, 2026