CVE-2019-11698: Input Validation
If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's browser history can be run and transmitted to the content page via drop event data. This allows for the theft of browser history by a malicious site.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-14/#CVE-2019-11698
Other sources
If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's browser history can be run and transmitted to the content page via drop event data. This allows for the theft of browser history by a malicious site.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 60.7 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 67 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 60.7 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 152.0-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 140.11.0esr-1~deb11u1Fixed in 140.10.2esr-1~deb12u1Fixed in 140.12.0esr-1~deb12u1Fixed in 140.10.2esr-1~deb13u1Fixed in 140.12.0esr-1~deb13u1Fixed in 140.11.0esr-1Fixed in 140.12.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:140.12.0esr-1~deb11u1Fixed in 1:140.10.1esr-1~deb12u1Fixed in 1:140.11.0esr-1~deb12u1Fixed in 1:140.10.1esr-1~deb13u1Fixed in 1:140.11.0esr-1~deb13u1Fixed in 1:140.11.0esr-1Fixed in 1:140.12.0esr-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.11.0esr-1~deb11u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.10.2esr-1~deb12u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.12.0esr-1~deb12u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.10.2esr-1~deb13u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.12.0esr-1~deb13u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.11.0esr-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.12.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.12.0esr-1~deb11u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.10.1esr-1~deb12u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.11.0esr-1~deb12u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.10.1esr-1~deb13u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.11.0esr-1~deb13u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.11.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.12.0esr-1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-9815
- CVE-2019-9816
- CVE-2019-9817
- CVE-2019-9818
- CVE-2019-9819
- CVE-2019-9820
- CVE-2019-11691
- CVE-2019-11692
- CVE-2019-11693
- CVE-2019-7317
- CVE-2019-9797
- CVE-2018-18511
- CVE-2019-11694
- CVE-2019-11698
- CVE-2019-5798
- CVE-2019-9800
- CVE-2019-9821
- CVE-2019-11695
- CVE-2019-11696
- CVE-2019-11697
- CVE-2019-11700
- CVE-2019-11699
- CVE-2019-11701
- CVE-2019-9814
Frequently Asked Questions
What is CVE-2019-11698?
CVE-2019-11698 is a vulnerability that allows an arbitrary query of a user's browser history to be run and transmitted to a content page via drop event data.
How severe is CVE-2019-11698?
CVE-2019-11698 has a severity score of 5.3, which is considered medium.
Which software is affected by CVE-2019-11698?
CVE-2019-11698 affects Firefox versions 67.0 and above, as well as Thunderbird versions 60.7.0 and above.
How can I fix CVE-2019-11698?
To fix CVE-2019-11698, update your Firefox installation to version 67.0 or higher, or update Thunderbird to version 60.7.0 or higher.
Where can I find more information about CVE-2019-11698?
You can find more information about CVE-2019-11698 in the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1543191), [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2019-13/)